Authentication
OAuth for AI assistants and apps, API keys for scripts. Every credential is bound to one workspace.
Every request carries a bearer token:
Authorization: Bearer <token>The token is either an API key or an OAuth access token. Both resolve to a connection: one user, one workspace, one access level.
API keys
Use an API key for your own scripts and integrations.
- Create keys in Settings → Developers. Give each key a name, a workspace and an access level.
- Keys look like
pp_live_…. The full key is shown once; PropertyPixel stores only a hash and the visible prefix. - The list shows when each key was last used.
- Keep keys on a server. Never put one in a browser, a mobile app or a public repository.
OAuth
ChatGPT, Claude and other MCP clients use OAuth 2.1 with PKCE. You don't set anything up: the client registers itself, opens the PropertyPixel sign-in page, and you choose a workspace and access level on the consent screen.
To build your own app, use the authorization code flow with PKCE (S256) against the PropertyPixel authorization server. Its metadata is published at https://mcp.propertypixel.app/.well-known/oauth-protected-resource, and dynamic client registration is enabled. Access tokens are short-lived JWTs; use the refresh token to get a new one.
Workspaces
A connection only ever sees the workspace chosen when it was created: its projects, photos, results and credit balance. To work in another workspace, create another key or connect again and pick it.
Your membership is checked on every request. If you leave the workspace, the connection stops working.
Access levels
| Access | Value | Can do |
|---|---|---|
| View only | read | List and read projects, photos, results and jobs. Pick results. Create download links. |
| View and edit | write | Everything above, plus create and delete projects and photos, upload, and run edits that spend credits. |
A view-only connection that calls a write operation gets 403 with code forbidden_scope. Reviewers in a team workspace can only hold view-only access; if your role is lowered to reviewer, an edit connection becomes view-only.
GET /v1/account returns scope.granted (what the connection was given) and scope.effective (what it can do now).
Revoking
Open Settings → Developers:
- Connected apps lists ChatGPT, Claude and other OAuth clients. Revoke signs the app out of PropertyPixel.
- API keys lists your keys. Revoke disables the key.
Revoking takes effect on the next request, which then gets 401 unauthorized.