# Open API

The Open API and MCP `api` tool are available to every signed-in account. Call
Kody over HTTPS at [api.kody.codes](https://api.kody.codes) (`/openapi.json` and
`/v1/*`). Interactive docs: [api-docs.kody.codes](https://api-docs.kody.codes).

## What it is

- **Open API** — JSON HTTP at [api.kody.codes](https://api.kody.codes)
  (`/openapi.json` and `/v1/*`).
- **MCP `api` tool** — run one Open API operation (`operationId` + `params`)
  from a connected agent. Use it to mint, list, and revoke scoped API tokens
  (`tokenCreate` / `tokenList` / `tokenRevoke`). There is no account UI for
  tokens.

For CLI `--local` setup and usage (CapabilityProxy / package-graph), see
[Local CLI execute](/docs/local-execute) (`guide:local_execute`). That path is
separate from Open API; some `/v1` routes exist so the CLI can hop to origin.

## Mint a scoped API token

With MCP `api` available, mint a short-lived token (value returned once):

```json
{
	"operationId": "tokenCreate",
	"params": {
		"name": "ci-bot",
		"scopes": ["account:read", "search:read"]
	}
}
```

Include `"local-execute"` in `scopes` only when a headless CLI needs
CapabilityProxy / package-graph over a `kody_at_…` token (see
[Local CLI execute](/docs/local-execute)). Put the value in the environment
(`KODY_API_TOKEN`); never paste it into chat.

List and revoke with `tokenList` / `tokenRevoke`, or the same operations over
HTTP.

## Metering

Each Open API operation (HTTPS, MCP `api`, CapabilityProxy hop, or package-graph
prep) meters as an observe-only `api_call`. Capability work behind the operation
still meters as usual.

## Where to go next

- [api-docs.kody.codes](https://api-docs.kody.codes) — interactive OpenAPI
- [Local CLI execute](/docs/local-execute) — `@kodycodes/cli execute --local`
- [Runtime and efficiency](/docs/platform-efficiency) — how cloud execute meters
  worker days
- Contributor detail:
  [Open API architecture](https://github.com/kentcdodds/kody/blob/main/docs/contributing/architecture/open-api.md)
