Authentication

Connect a local agent, authenticate a headless script, or create a limited personal key.

Agent login

Run the supported CLI with Node.js 22 or newer. It opens a dedicated sign-in page, validates its loopback callback, and stores a separate agent session. You do not need to extract a token from your browser.

bash
npx -y -p @crowdlisten/harness@2.2.3 crowdlisten-harness login

Restart your agent after setup, then call recall({ mode: "connection" }). The harness refreshes its saved session and coordinates concurrent clients. Keep its credential file private; logout clears the local connection. This browser-assisted login requires a local browser and is not a device-code grant.

Headless email and password login

A confirmed email account with a password can obtain a session directly from the token endpoint below. SSO-only accounts must use provider sign-in; do not submit your Google or Microsoft password to this endpoint. MFA or account policy may require an additional authentication step.

text
POST https://fnvlxtzonwybshtvrzit.supabase.co/auth/v1/token?grant_type=password
apikey: PROJECT_PUBLISHABLE_KEY
Content-Type: application/json

{"email":"YOUR_EMAIL","password":"YOUR_PASSWORD"}
Run a read-only connection check without a browser
python
# Python 3: prompts keep passwords out of shell history and process arguments.
import getpass, json, urllib.request
AUTH_URL = "https://fnvlxtzonwybshtvrzit.supabase.co"
PUBLIC_KEY = "eyJhbGciOiJIUzI1NiIsInR5cCI6IkpXVCJ9.eyJpc3MiOiJzdXBhYmFzZSIsInJlZiI6ImZudmx4dHpvbnd5YnNodHZyeml0Iiwicm9sZSI6ImFub24iLCJpYXQiOjE3NTY4NjExMjksImV4cCI6MjA3MjQzNzEyOX0.KAoEVMAVxqANcHBrjT5Et_9xiMZGP7LzdVSoSDLxpaA"
email = input("CrowdListen email: ").strip()
password = getpass.getpass("Password: ")
request = urllib.request.Request(
    AUTH_URL + "/auth/v1/token?grant_type=password",
    data=json.dumps({"email": email, "password": password}).encode(),
    headers={"apikey": PUBLIC_KEY, "Content-Type": "application/json"})
with urllib.request.urlopen(request) as response:
    session = json.load(response)
# Use the access token in memory. Do not print or commit the session.
request = urllib.request.Request(
    "https://agent.crowdlisten.com/agent/v1/connection",
    headers={"Authorization": "Bearer " + session["access_token"]})
with urllib.request.urlopen(request) as response:
    print("Connection check:", response.status)
# Long-running services must securely store refresh_token and serialize refresh.

The project publishable key identifies the application and is public. It is not a service-role key and does not identify a user. The returned access_token is the user bearer; expires_in and expires_at describe its lifetime.

Refresh and revoke

Send {"refresh_token":"SAVED_REFRESH_TOKEN"} to https://fnvlxtzonwybshtvrzit.supabase.co/auth/v1/token?grant_type=refresh_token, with the same headers. Persist the newly returned refresh token atomically and serialize refresh requests across workers. Never replay a failed write automatically. Reauthenticate on an invalid or revoked refresh token.

To revoke a user session, send POST https://fnvlxtzonwybshtvrzit.supabase.co/auth/v1/logout?scope=local with the project key and the session bearer. Existing access tokens may remain valid until expiry. Personal keys are revoked separately below.

Personal key permissions

Sign in once to establish the account that owns the key. Create or revoke keys in Agent access, or call /api/user/keys with a user session. Requiring that session prevents one leaked script key from minting more keys. Personal keys are limited credentials, not replacements for every product API.

CredentialAccepted operationsBoundary
ingest keyPOST /agent/v1/ingest/contentAlso accepts ingest coverage, filter, deep-extract, trigger-pipeline, research, research/jobs and collection/jobs, plus GET research/jobs and research/jobs/{id}. Processing and research can incur usage; workspace access and limits still apply.
export keyGET /agent/v1/export/*Raw export must be enabled for the account by CrowdListen.
* keyBoth of the aboveDoes not grant user-session APIs, admin access, or additional workspaces.
User sessionProduct APIs and key managementAccount role, workspace membership, feature access, and billing rules still apply.

Raw export is currently restricted to accounts explicitly enabled by CrowdListen (the legacy database field is whitelisted) and administrators. Creating an export key does not enable this feature. Contact CrowdListen to request access. A 401 means authentication failed; a 403 means the credential is recognized but access is denied.

Account recovery

Use Reset password for an existing email account. If sign-in reports an unconfirmed email, use its resend control. On the signup confirmation screen, choose “Use a different email” to correct an address and submit signup again. Confirmation links opened on another device can be followed by a normal password sign-in.

Browse every published API operation. The catalogue includes connector callbacks and administrative operations; listing an endpoint does not grant permission to call it.