# API keys and Google sign-in | WhatsDo Docs

URL: https://whatsdo.ai/docs/keys-and-sign-in

Skip to contentDocumentationTools reference

Sign inGet API key

Search the docs menu

Get started
- Overview
- Quickstart
- Connect your agent
- Keys and sign-in

Guides
- Book a table
- Shortlist restaurants
- Café and a walk
- Massage, salon, yoga
- Local market signals

Reference
- Tools
- Booking statuses
- Limits
- Errors and fixes

# Keys and sign-in

Sign-in for agents, a personal key for scripts.

## Sign in

For agents acting for a person: Claude, Claude Code and ChatGPT. Cursor, Gemini CLI and Codex take sign-in or an API key. Add the server address. The client opens a WhatsDo sign-in, you sign in with Google or an emailed code and approve access. If you are already signed in to the developer portal in that browser, you only click Allow. No key to copy.

Under the hood this is OAuth 2.1 with PKCE (S256) and dynamic client registration, so there is no client ID to paste. An unauthenticated call returns 401 with a WWW-Authenticate header that points the client to the discovery documents.

text

```
GET  /.well-known/oauth-protected-resource/mcp
GET  /.well-known/oauth-authorization-server
POST /oauth/register     # dynamic client registration
GET  /oauth/authorize    # PKCE S256, then Google sign-in, then consent
POST /oauth/token        # access and refresh tokens
```

Access tokens last one hour. Refresh tokens last 30 days and rotate on use.

## API key

For scripts, servers, VS Code and clients without sign-in.

- 1Open Get API key and sign in with Google or an emailed code. The code expires in ten minutes.
- 2Create a key and copy it. It is shown once. Tick bookings:write if your agent books: a new key has only search and bookings:read by default.
- 3Send it on every request as Authorization: Bearer <key>.Or pick your agent on the setup page: it creates a key with search, bookings:read and bookings:write and writes the setup prompt for you.

- Keys start with whatsdo_pat_.
- A key is valid for 90 days. Create a new one before it expires.
- You can have up to 10 active keys.
- A key is shown once, at creation. If you lose it, create a new one.bash

```
export WHATSDO_API_KEY="whatsdo_pat_..."

curl https://app.whatsdo.com/mcp/ -H "Authorization: Bearer $WHATSDO_API_KEY" ...
```

Keep the key on your server or in local config. Do not put it in browser code or in a public repository.

## Scopes

Each tool needs one scope. A missing scope fails that one call, not the session.

| Scope | Tools |
| --- | --- |
| search | search, place_details, get_booking_requirements |
| bookings:read | my_bookings, calendar_free_slots, calendar_check_conflict |
| bookings:write | book, cancel_booking, continue_booking |
| profile:write | set_location, remember_preference |

Search and booking need search, bookings:read and bookings:write. A key created in the portal has only search and bookings:read unless you tick bookings:write. Add profile:write only if your agent saves a default location or preferences.

A call without its scope fails with Missing required scope: <scope>.

## Whose account books

Bookings are made as the signed-in WhatsDo account. Name and phone for a booking come from that account’s profile. Do not ask the person for them.

On this page

- Sign in
- API key
- Scopes
- Whose account booksCopy page

© WhatsDo

## Product

MCPPlacesBookingPayments

## Build

ConnectDocsUse cases

## WhatsDo

For businessesTalk to usPrivacy policyTerms of serviceCookie policySite map
