Skip to main content
The REST API takes either of two credentials:
  • OAuth 2.0 Bearer token — the same token you already have from the MCP flow. Nothing extra to set up.
  • API key — a long-lived X-API-Key credential for scripts and integrations that can’t run an OAuth flow. Create one with POST /v1/api-keys (or moneda api-key create).

Plan availability

The REST API, MCP server and CLI are available on every plan today. Access is governed by a single feature flag, so this can change: if your plan does not include them, calls return 403 PLAN_UPGRADE_REQUIRED and the message names the plans that do. The /v1/api-keys endpoints behave slightly differently. Creating a key when your plan does not include the surfaces is refused by the mint itself, so you get one error that names the key rather than a blanket surface error. Listing and revoking keys stay available on every plan, so a key you already issued can always be reviewed and revoked.

How it works

Send whichever credential you have:
Your token is obtained through the standard MCP OAuth flow. If you’ve already connected an AI assistant to Moneda, you have a valid token.
The REST API and MCP server share the same authentication system. A token that works for MCP will work for the REST API, and vice versa.

Example request

With an OAuth Bearer token:
With an API key — the header name is X-API-Key, and the key is sent raw with no Bearer prefix:
The same key works for the CLI via --api-key on any command, which overrides a stored OAuth token:

Scopes

The REST API enforces the same 36 OAuth scopes as MCP. Each endpoint requires one or more scopes to be present on your token. For example, GET /v1/balances requires the read:balances scope. If your token is missing a required scope, the API returns a 403 Forbidden response with a message indicating which scope is needed.
See the full list of scopes and what they grant access to on the Scopes page.

Unauthenticated endpoints

The GET /v1/health endpoint does not require authentication. You can use it to verify the API is reachable:

Error responses

When authentication fails, the API returns standard HTTP status codes:

What’s next?

API Endpoints

See all 158 endpoints and what scopes they require.

Scopes

Full reference of all 36 OAuth scopes.

MCP Authentication

Learn how the underlying OAuth flow works.

OpenAPI Spec

Explore the API interactively with Swagger UI.