# Templa administrative API authentication

This integration is restricted to an authorized store administrator. Create a token in the seller dashboard MCP tab and store it as a secret in your local MCP client or server environment. Send Authorization: Bearer TOKEN to POST https://templa.app/api/mcp. Never include it in a URL, public repository, screenshot, browser bundle or marketing agent prompt. The token grants administrative access, including mutation tools beyond the read-only OpenAPI subset. It does not authenticate customer checkout or grant a template purchase.

The server checks the token hash, revocation, expiry, current owner admin status and rate limit before dispatch. Revocation is available in the seller dashboard. Responses use {"ok":false,"error":"..."}: 401 for missing/invalid credentials, 403 for revoked/expired tokens or lost admin authority, 400 for invalid/oversized JSON, 422 for invalid input, 429 for rate limits, and 500 for internal failures. Missing resources may return 404. Do not retry authorization errors as purchases, bypass access checks or infer ownership from email, timing or amount.

- [Templa developer resources](https://templa.app/developers.md)
- [OpenAPI schema](https://templa.app/openapi.json)
- [Contact support](https://templa.app/contact)
