# BatonDeck

> The hosted HDTP platform: the portal, the /v1 API and the owner MCP server, and where each answers.

BatonDeck runs HDTP identities for people who would rather not run a node. Three doors reach the same platform, each answering on its own host in production:

| Door | Where | For |
|---|---|---|
| The portal | `https://app.batondeck.com` | a person, signed in with the portal session |
| [The /v1 API](/cloud/api/) | `https://api.batondeck.com/v1` | a program, with a workspace API key |
| [The owner MCP server](/cloud/mcp/) | `https://mcp.batondeck.com/mcp` | an agent, over OAuth |

Every action the owner MCP takes is a `/v1` operation run through the same pipeline, with the same permission; the [MCP reference](/cloud/mcp/) names the operation behind each action.

## Keys

A workspace API key: `bd_<id>_<secret>`. Minted by a person on the portal's Agents page (Agent keys), which calls `POST /v1/workspace/keys` with a session; a key cannot mint one, because minting needs step-up. Shown once, hashed at rest. Malformed, unknown and revoked keys answer identically.
