> ## Documentation Index
> Fetch the complete documentation index at: https://docs.pretectum.io/llms.txt
> Use this file to discover all available pages before exploring further.

# API Reference

> Explore the Pretectum API to programmatically access and search your data objects

Welcome to the Pretectum API Reference. This documentation provides everything you need to integrate with the Pretectum platform and access your master data programmatically.

## Base URL

All API requests should be made to:

```
https://api.pretectum.io
```

## Authentication

The Pretectum API authenticates with an API key, or with the access token of a signed-in Pretectum
user. A key is a long-lived credential, so an integration built on one has no token to exchange and
nothing to refresh; a token suits a tool acting on a person's behalf, see [Access Tokens](#access-tokens).

<Card title="API Keys" icon="key" href="/api-reference/authentication/api-keys">
  Learn how to create, use and manage API keys
</Card>

### How Authentication Works

1. **Create a key**: In the Pretectum app, go to **Configuration → API Keys** and create one. It is
   shown once, at creation.
2. **Send it**: Put the key in the `Authorization` header of every request.

```bash theme={null}
Authorization: pre_your_api_key
```

### Access Tokens

The API also accepts the access token of a signed-in Pretectum user in the same header, bare or
as `Bearer <token>`. A request made with a token acts as that user, with the user's own roles
and business area assignments, and is audited under the user's name. The token has to be issued
by signing in through a client registered for the API; today that is the [MCP server](/ai-tools/mcp-server),
so this is the credential an assistant holds after you sign in there. A token copied out of the
Pretectum web app is refused. Tokens expire, so they suit tools that act on a person's behalf
during a session; an integration that runs unattended should use an API key.

## Available Endpoints

<CardGroup cols={2}>
  <Card title="API Keys" icon="lock" href="/api-reference/authentication/api-keys">
    Create and manage the keys that authenticate your requests
  </Card>

  <Card title="Search Data Objects" icon="magnifying-glass" href="/api-reference/dataobjects/search">
    Search across your master data objects
  </Card>

  <Card title="MCP Server" icon="plug" href="/ai-tools/mcp-server">
    Use the API from Claude Code, Cursor or VS Code
  </Card>
</CardGroup>

## Rate Limiting

API requests are subject to rate limiting. If you exceed the rate limit, you will receive a `429 Too Many Requests` response. Please implement appropriate retry logic with exponential backoff.

## Error Handling

The API returns standard HTTP status codes to indicate success or failure:

| Status Code | Description |
| - | - |
| `200` | Success |
| `400` | Bad Request - Invalid parameters |
| `401` | Unauthorized - Invalid, missing, inactive or expired API key, or an invalid or expired access token |
| `403` | Forbidden - Insufficient permissions |
| `404` | Not Found - Resource does not exist |
| `429` | Too Many Requests - Rate limit exceeded |
| `500` | Internal Server Error |

## Need Help?

If you have questions or need assistance, contact our support team at [support@pretectum.com](mailto:support@pretectum.com).
