Skip to content

BatonDeck

View as Markdown

BatonDeck runs HDTP identities for people who would rather not run a node. Three doors reach the same platform, each answering on its own host in production:

Door Where For
The portal https://app.batondeck.com a person, signed in with the portal session
The /v1 API https://api.batondeck.com/v1 a program, with a workspace API key
The owner MCP server https://mcp.batondeck.com/mcp an agent, over OAuth

Every action the owner MCP takes is a /v1 operation run through the same pipeline, with the same permission; the MCP reference names the operation behind each action.

A workspace API key: bd_<id>_<secret>. Minted by a person on the portal’s Agents page (Agent keys), which calls POST /v1/workspace/keys with a session; a key cannot mint one, because minting needs step-up. Shown once, hashed at rest. Malformed, unknown and revoked keys answer identically.