Base URL
All API requests should be made to:Authentication
The Pretectum API authenticates with an API key, or with the access token of a signed-in Pretectum user. A key is a long-lived credential, so an integration built on one has no token to exchange and nothing to refresh; a token suits a tool acting on a person’s behalf, see Access Tokens.API Keys
Learn how to create, use and manage API keys
How Authentication Works
- Create a key: In the Pretectum app, go to Configuration → API Keys and create one. It is shown once, at creation.
- Send it: Put the key in the
Authorizationheader of every request.
Access Tokens
The API also accepts the access token of a signed-in Pretectum user in the same header, bare or asBearer <token>. A request made with a token acts as that user, with the user’s own roles
and business area assignments, and is audited under the user’s name. The token has to be issued
by signing in through a client registered for the API; today that is the MCP server,
so this is the credential an assistant holds after you sign in there. A token copied out of the
Pretectum web app is refused. Tokens expire, so they suit tools that act on a person’s behalf
during a session; an integration that runs unattended should use an API key.
Available Endpoints
API Keys
Create and manage the keys that authenticate your requests
Search Data Objects
Search across your master data objects
MCP Server
Use the API from Claude Code, Cursor or VS Code
Rate Limiting
API requests are subject to rate limiting. If you exceed the rate limit, you will receive a429 Too Many Requests response. Please implement appropriate retry logic with exponential backoff.
