Skip to content

KYB from your onboarding flow, or from an AI agent

Organization API keys and an MCP server give your systems the same cases, runs and reports your analysts use, with the same gates.

Request API access

API keys

  • Keys belong to an organization and look like otk_<prefix>_<secret>. We store only a keyed hash; the key is shown once.
  • Scopes: read, estimate, start. A key expires after 1 to 365 days (90 by default) and can be revoked at any time; the next call sees it.
  • Every call, refused ones included, is written to your organization’s audit log.

MCP tools

The MCP server exposes five tools over stdio, authenticated with one key per server process. Each call runs inside the key’s organization; a case in another organization is never found.

ToolScopeArgumentsWhat it does
list_casesreadnoneYour organization's cases, their permission state and subject count.
estimateestimatecase, subjectCost and minutes for one run, from the real plan. Reads only.
start_investigationstartcase, subject, attestedQueues a run. Refused unless attested is true and the case has its permission check recorded.
job_statusreadjob_idStatus of one job.
get_reportreadcase, subject, versionLatest or given report version: hashes, sign-off and the client summary.

Same rules as the app

A run started over the API passes the same case gate as one started by an analyst: a recorded purpose and lawful basis, and an explicit attestation. A report comes back with its hashes, its sign-off state and the client summary, never the internal working file with analyst notes. Use stays under the Acceptable Use Policy.

API and MCP | OSINTTotal