The REST API answers to a scoped API key. The MCP server answers to OAuth (recommended) or the same key. Both are free on every plan.
Every organization route under /api/orgs/:orgId answers to a key the same way it answers to a signed-in browser: create, read, update and delete links, read click analytics, manage domains and members.
Getting a key: while signed in, create one for an organization you own from API keys, or directly: POST /api/orgs/:orgId/api-keys with {"name": "..."}. The response carries the raw key once.
Revoking one: DELETE /api/orgs/:orgId/api-keys/:keyId, or from the same page. Takes effect at once.
GET /api/orgs/org_id/links
Authorization: Bearer rdyrct_live_...
A hosted MCP endpoint at https://rdyrct.com/api/mcp, stateless, for an AI chatbot's connectors.
OAuth (recommended): rdyrct is a full OAuth 2.1 authorization server for this endpoint. Point an MCP client at the URL above and it discovers the flow itself from /.well-known/oauth-protected-resource/api/mcp, no key to copy or lose. Revoke a connection any time from API keys' MCP tab.
API key: the same scoped key as the REST API works too, with the same header.
Tools: create_link, update_link, delete_link, list_links, get_link_stats, get_org_stats, get_plan_usage, invite_member, generate_qr_code. Every tool but the last takes an optional org_id, and assumes your sole organization when it is left out.
POST /api/mcp
Authorization: Bearer rdyrct_live_...
Content-Type: application/json
Accept: application/json, text/event-stream
{
"jsonrpc": "2.0",
"id": 1,
"method": "tools/call",
"params": {
"name": "create_link",
"arguments": { "destination": "https://example.com/blog/post" }
}
}