Access and Permissions
Every API key has an explicit authorization scope. The API evaluates that scope on every REST and MCP request.
Permission Dimensions
Dataset Access
A key may allow:
- ICD
- ICDB
- Both datasets
Route visibility does not grant access. The key must be authorized for the requested dataset.
Record Scope
A key may be limited to an approved subset of records or entities. Filters cannot expand that scope.
Capability Access
A key may independently allow or deny capabilities such as:
- Structured search and detail retrieval
- Media access
- Geo Manifests
- Natural Language Search
- Domain GenAI
- MCP access
Usage Controls
Accounts may also have credit, quota, and rate-limit controls. A valid key can still receive a usage-related rejection when a control is reached.
Privacy-Preserving Responses
For some unavailable, missing, or unauthorized records, the API may use a response that does not confirm whether content exists outside the caller's scope. Integrations must not infer broader dataset contents from empty or not-found responses.
MCP
MCP tools apply the same dataset, record, feature, quota, and credit controls as the equivalent REST routes. Connecting /mcp-all does not override the key's permissions.
Troubleshooting
- 401 Unauthorized: the key is missing, invalid, or sent incorrectly.
- 403 Forbidden: the key lacks a required dataset or capability.
- 404 Not Found: the identifier is unavailable within the request context, or the route is incorrect.
- 429 Too Many Requests: wait for the indicated interval and apply backoff.
Contact IntelCenter support if the assigned scope does not match the intended integration.
