# Developer API

*Not yet available* · Last updated 2026-10-08

> This document describes the platform foundation under development. Details may change before launch.

The planned programmatic access to Landmate: API keys, OAuth 2.1 with PKCE, and MCP for AI tools.

The developer API is **not available yet**. This page describes the foundation being built so that integrations can be planned; details may change before launch.

## Ways to connect

- **API keys** for your own scripts and servers. Only workspace Owners can create and revoke them, and doing so asks for a fresh sign-in.
- **OAuth 2.1 with PKCE** for apps that act on behalf of a Landmate user, without ever seeing that user's password.
- **MCP (Model Context Protocol)** so that AI tools you choose can work with your workspace through the same scopes and checks.

## Scopes

API keys and OAuth tokens carry **scopes**. What a request may do is the intersection of three things, checked again on every request:

1. the scopes on the key or token;
2. the current role of the member who created it;
3. that member's location access.

If the member's role is reduced or they are removed from the workspace, their keys and authorizations lose that access immediately (removal revokes them).

| Scope | Includes |
| --- | --- |
| `workspace:read` — Read the workspace, its members and locations | View the workspace, See members, View locations |
| `workspace:write` — Change workspace details and manage locations | Change workspace details, Create and manage locations |
| `files:read` — Read files | View files |
| `files:write` — Upload files | Upload files |
| `audit:read` — Read the audit log | Read the audit log |

## Not yet available

There are no public endpoints, keys or client registrations yet. This page will be updated with endpoint documentation when the API launches.
