> ## Documentation Index
> Fetch the complete documentation index at: https://docs.gtm-api.com/llms.txt
> Use this file to discover all available pages before exploring further.

# Generate cloud-browser access key

> Mint a cloud-browser access key (smart-link) on a browser. Returns the whole minted entry in result.access_key, whose `key` field is the raw cb_ak_ token (shown once), AND result.public_connect_url, the ready-to-share link to hand to whoever opens it (no platform account needed on their side). Pass result.access_key.key, never result.access_key, to revoke_cloud_browser_access_key. `purpose` decides what the page behind the link does: `relogin` walks them through signing the LinkedIn session back in and re-binds the browser once they confirm, `share` just hands them the browser to drive. Optional ttl_hours / max_connects / allowed_ips / allowed_countries scope the key; send_to_email also mails the link to whoever holds the LinkedIn password (a fixed mail, no text to supply). DANGEROUS: both the key and the link are bearer secrets granting remote browser access.

Contract:
- MCP tool `generate_cloud_browser_access_key`, registry package `mcp.linkedin/antidetect_browsers`, mount `linkedin.browsers`.
- Operation `action`, response envelope `action`.
- Flags: dangerous: the MCP layer gates it behind a preview/commit token, and the effect cannot be undone through this API.



## OpenAPI

````yaml /api-reference/linkedin/openapi.yaml post /api/antidetect-browsers/generate-cloud-browser-access-key
openapi: 3.0.3
info:
  title: 'GTM API public contract: gtm.service.linkedin'
  description: >-
    Connected LinkedIn accounts and everything driven through them: account
    health and smart limits, conversations and messages, the connection graph,
    outbound posting, scraping, profile and company enrichment, and the
    antidetect browsers that execute it all.


    GENERATED. This document is projected from the Zod MCP tool registry in
    `product/mcp/gtm.mcp` (one tool per public endpoint, 1:1). Do not edit it by
    hand; edit the tool definition and regenerate with `pnpm openapi:public`.


    Surface: the public `/api` contract of `gtm.service.linkedin`, 189
    operations. This is the only OpenAPI document the platform publishes.
    Internal (`/internal`) and health endpoints are deliberately absent: they
    are not part of any contract, they can change without notice, and the
    service source is their only description.


    Conventions:

    - Auth is a bearer JWT, optionally narrowed by the `Team-SID` header.

    - Every success body is an MCP envelope: `success: true` plus one typed
    `operation` shape (`search`, `get`, `create`, `update`, `delete`, `metrics`,
    `group_by`, `action`), and a `meta` block with `trace_id` for support.

    - Every failure is the same `McpError` envelope with a code from a fixed
    16-code taxonomy, so a client maps errors once.

    - Lists page with `page_size` (0 to 500, default 50) plus an opaque forward
    `cursor`; `page_size: 0` returns counts only.

    - On `GET` and `DELETE`, object-valued query parameters (`filter`, `sort`)
    travel as JSON text and array-valued ones repeat as `name[]=value`.

    - The MCP-only `_meta` field (usage analytics) never reaches the backend and
    is not part of this contract.
  version: '1.0'
  contact:
    name: GTM API
    url: https://gtm-api.com
    email: support@gtm-api.com
  license:
    name: Proprietary
    url: https://gtm-api.com/license
servers:
  - url: https://app.gtm-api.com/linkedin/v4
    description: Production, through the app.gtm-api.com gateway
security:
  - BearerJwt: []
    TeamSid: []
tags:
  - name: antidetect_browser_logs
    description: >-
      Registry package `mcp.linkedin/antidetect_browser_logs`, served on MCP
      mount `linkedin.browsers`.
  - name: antidetect_browser_proxies
    description: >-
      Registry package `mcp.linkedin/antidetect_browser_proxies`, served on MCP
      mount `linkedin.browsers`.
  - name: antidetect_browsers
    description: >-
      Registry package `mcp.linkedin/antidetect_browsers`, served on MCP mount
      `linkedin.browsers`.
  - name: cloud_browser_sessions
    description: >-
      Registry package `mcp.linkedin/cloud_browser_sessions`, served on MCP
      mount `linkedin.browsers`.
  - name: cloud_browsers
    description: >-
      Registry package `mcp.linkedin/cloud_browsers`, served on MCP mount
      `linkedin.browsers`.
  - name: data_requests
    description: >-
      Registry package `mcp.linkedin/data_requests`, served on MCP mount
      `linkedin.data`.
  - name: linkedin_account_activity_log
    description: >-
      Registry package `mcp.linkedin/linkedin_account_activity_log`, served on
      MCP mount `linkedin.account-monitor`.
  - name: linkedin_account_block_log
    description: >-
      Registry package `mcp.linkedin/linkedin_account_block_log`, served on MCP
      mount `linkedin.account-monitor`.
  - name: linkedin_account_quota_hits
    description: >-
      Registry package `mcp.linkedin/linkedin_account_quota_hits`, served on MCP
      mount `linkedin.account-monitor`.
  - name: linkedin_account_smart_limits
    description: >-
      Registry package `mcp.linkedin/linkedin_account_smart_limits`, served on
      MCP mount `linkedin.accounts`.
  - name: linkedin_account_snapshots
    description: >-
      Registry package `mcp.linkedin/linkedin_account_snapshots`, served on MCP
      mount `linkedin.account-monitor`.
  - name: linkedin_account_sync_runs
    description: >-
      Registry package `mcp.linkedin/linkedin_account_sync_runs`, served on MCP
      mount `linkedin.account-monitor`.
  - name: linkedin_accounts
    description: >-
      Registry package `mcp.linkedin/linkedin_accounts`, served on MCP mount
      `linkedin.accounts`.
  - name: linkedin_auto_scrape_results
    description: >-
      Registry package `mcp.linkedin/linkedin_auto_scrape_results`, served on
      MCP mount `linkedin.auto-scrapes`.
  - name: linkedin_auto_scrape_runs
    description: >-
      Registry package `mcp.linkedin/linkedin_auto_scrape_runs`, served on MCP
      mount `linkedin.auto-scrapes`.
  - name: linkedin_auto_scrapes
    description: >-
      Registry package `mcp.linkedin/linkedin_auto_scrapes`, served on MCP mount
      `linkedin.auto-scrapes`.
  - name: linkedin_benchmarks
    description: >-
      Registry package `mcp.linkedin/linkedin_benchmarks`, served on MCP mount
      `linkedin.account-monitor`.
  - name: linkedin_connection_invitations
    description: >-
      Registry package `mcp.linkedin/linkedin_connection_invitations`, served on
      MCP mount `linkedin.network`.
  - name: linkedin_connection_requests
    description: >-
      Registry package `mcp.linkedin/linkedin_connection_requests`, served on
      MCP mount `linkedin.network`.
  - name: linkedin_connections
    description: >-
      Registry package `mcp.linkedin/linkedin_connections`, served on MCP mount
      `linkedin.network`.
  - name: linkedin_conversations
    description: >-
      Registry package `mcp.linkedin/linkedin_conversations`, served on MCP
      mount `linkedin.messaging`.
  - name: linkedin_custom_requests
    description: >-
      Registry package `mcp.linkedin/linkedin_custom_requests`, served on MCP
      mount `linkedin.platform`.
  - name: linkedin_enrichment
    description: >-
      Registry package `mcp.linkedin/linkedin_enrichment`, served on MCP mount
      `linkedin.enrichment`.
  - name: linkedin_followers
    description: >-
      Registry package `mcp.linkedin/linkedin_followers`, served on MCP mount
      `linkedin.network`.
  - name: linkedin_messages
    description: >-
      Registry package `mcp.linkedin/linkedin_messages`, served on MCP mount
      `linkedin.messaging`.
  - name: linkedin_posting
    description: >-
      Registry package `mcp.linkedin/linkedin_posting`, served on MCP mount
      `linkedin.content`.
  - name: linkedin_scraping
    description: >-
      Registry package `mcp.linkedin/linkedin_scraping`, served on MCP mount
      `linkedin.scraping`.
paths:
  /api/antidetect-browsers/generate-cloud-browser-access-key:
    post:
      tags:
        - antidetect_browsers
      summary: Generate cloud-browser access key
      description: >-
        Mint a cloud-browser access key (smart-link) on a browser. Returns the
        whole minted entry in result.access_key, whose `key` field is the raw
        cb_ak_ token (shown once), AND result.public_connect_url, the
        ready-to-share link to hand to whoever opens it (no platform account
        needed on their side). Pass result.access_key.key, never
        result.access_key, to revoke_cloud_browser_access_key. `purpose` decides
        what the page behind the link does: `relogin` walks them through signing
        the LinkedIn session back in and re-binds the browser once they confirm,
        `share` just hands them the browser to drive. Optional ttl_hours /
        max_connects / allowed_ips / allowed_countries scope the key;
        send_to_email also mails the link to whoever holds the LinkedIn password
        (a fixed mail, no text to supply). DANGEROUS: both the key and the link
        are bearer secrets granting remote browser access.


        Contract:

        - MCP tool `generate_cloud_browser_access_key`, registry package
        `mcp.linkedin/antidetect_browsers`, mount `linkedin.browsers`.

        - Operation `action`, response envelope `action`.

        - Flags: dangerous: the MCP layer gates it behind a preview/commit
        token, and the effect cannot be undone through this API.
      operationId: generate_cloud_browser_access_key
      requestBody:
        required: true
        content:
          application/json:
            schema:
              $ref: '#/components/schemas/GenerateCloudBrowserAccessKeyRequest'
      responses:
        '200':
          description: '`action` success envelope.'
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/GenerateCloudBrowserAccessKeyResponse'
        4XX:
          $ref: '#/components/responses/McpClientError'
        5XX:
          $ref: '#/components/responses/McpServerError'
components:
  schemas:
    GenerateCloudBrowserAccessKeyRequest:
      type: object
      description: Request body of `generate_cloud_browser_access_key`.
      properties:
        sid:
          type: string
          minLength: 18
          maxLength: 18
          pattern: ^ab_br_
          description: Antidetect browser sid (ab_br_…).
        ttl_hours:
          type: integer
          minimum: 1
          maximum: 720
          description: >-
            Key lifetime in hours (default 8; the link is a bearer secret, keep
            it short). Sets expires_at on the entry.
        max_connects:
          type: integer
          minimum: 1
          maximum: 1000
          description: >-
            Cap on CONCURRENT sessions held on this key, counted live at
            connect. Not a lifetime quota: a key does not spend itself and never
            becomes exhausted. Omit for unlimited.
        allowed_ips:
          type: array
          items:
            type: string
            maxLength: 45
          description: IP allow-list checked at connect time.
        allowed_countries:
          type: array
          items:
            type: string
            minLength: 2
            maxLength: 2
          description: ISO country allow-list checked at connect time.
        purpose:
          type: string
          enum:
            - relogin
            - recruiter_relogin
            - share
          description: >-
            What the page behind the link does: relogin = sign the LinkedIn
            session back in and re-bind the browser on confirm (default); share
            = drive the browser, no sign-in step; recruiter_relogin = the
            relogin flow aimed at LinkedIn Recruiter (2026-09-15): the cloud
            browser opens on linkedin.com/talent so the seat holder signs the
            Recruiter session back in, and the confirmed restart re-checks the
            account's recruiter_status.
        send_to_email:
          type: string
          maxLength: 255
          format: email
          description: >-
            Also email the link to this address, typically the person who holds
            the LinkedIn password and has no account on the platform. The mail
            is queued after the key is committed; result.sent_to_email echoes
            the address. A malformed address is 422 and mints nothing.
      required:
        - sid
    GenerateCloudBrowserAccessKeyResponse:
      type: object
      properties:
        success:
          type: boolean
          enum:
            - true
        operation:
          type: string
          enum:
            - action
        action:
          type: string
          description: kebab-case verb; matches the route segment.
        item:
          type: object
          nullable: true
          properties:
            sid:
              type: string
            team_sid:
              type: string
            linkedin_account_sid:
              type: string
              nullable: true
            automation_server_sid:
              type: string
              nullable: true
            account_share_sid:
              type: string
              nullable: true
            share_role:
              type: string
              nullable: true
              enum:
                - owner
                - holder
                - giver
                - receiver
            vendor_provider:
              type: string
              enum:
                - gologin
                - multilogin
                - adspower
                - dolphin
            vendor_name:
              type: string
              nullable: true
            vendor_profile_id:
              type: string
              nullable: true
            browser_owner:
              type: string
              enum:
                - platform
                - customer
            status:
              type: string
              enum:
                - stopped
                - queued_to_start
                - initializing
                - running
                - idle
                - queued_to_stop
                - start_issue
                - running_issue
                - login_issue
                - restricted
                - client_error_investigation
                - support_error_investigation
                - maintenance
                - shared_out
                - subscription_required
            error_reason:
              type: string
              nullable: true
            fail_count:
              type: number
            last_fail_at:
              type: string
              nullable: true
            logout_count:
              type: number
            last_logout_at:
              type: string
              nullable: true
            last_start_at:
              type: string
              nullable: true
            last_health_check_at:
              type: string
              nullable: true
            last_activity_at:
              type: string
              nullable: true
            antidetect_browser_proxy_sid:
              type: string
              nullable: true
            proxy_country_code:
              type: string
              nullable: true
            custom_proxy:
              type: object
              nullable: true
              properties:
                ip:
                  type: string
                port:
                  type: integer
                mode:
                  type: string
                username:
                  type: string
                  nullable: true
                exit_ip:
                  type: string
                  nullable: true
                latency_ms:
                  type: integer
                  nullable: true
              required:
                - ip
                - port
                - mode
                - username
                - exit_ip
                - latency_ms
            proxy_5g:
              type: boolean
              description: >-
                5G Proxy add-on: the browser runs on the dedicated 5G mobile
                route (faster command execution, fewer retries). Each flagged
                browser occupies one add-on slot.
            cloud_browser_access:
              type: array
              items:
                type: object
                properties:
                  key:
                    type: string
                    nullable: true
                    minLength: 18
                    maxLength: 18
                    pattern: ^cb_ak_
                    description: >-
                      The bearer token itself, in full, for a caller holding
                      can_manage_cloud_browser_external_links (the permission
                      that mints it: reading a key is the same power as minting
                      one, since the public connect checks nothing but the key).
                      null for every other caller; the entry stays so the link,
                      its expiry and its use can still be listed. On
                      cloud-browser-sessions it is masked to the last 4.
                  expires_at:
                    type: string
                    nullable: true
                    description: >-
                      ISO 8601 expiry; null means it never expires. Checked at
                      connect and never again, so a session can outlive its own
                      key.
                  max_connects:
                    type: number
                    nullable: true
                    description: >-
                      Cap on CONCURRENT sessions on this key; null means
                      unlimited.
                  allowed_ips:
                    type: array
                    nullable: true
                    items:
                      type: string
                  allowed_countries:
                    type: array
                    nullable: true
                    items:
                      type: string
                  purpose:
                    type: string
                    enum:
                      - relogin
                      - recruiter_relogin
                      - share
                    description: >-
                      What the public page behind the link does. Stamped at mint
                      and never re-negotiated at connect, because the visitor is
                      unauthenticated. Absent on keys minted before the field
                      existed, which the backend reads as relogin.
                required:
                  - key
                  - expires_at
                  - max_connects
                  - allowed_ips
                  - allowed_countries
              description: >-
                The smart links minted on this browser; the key itself only for
                a caller holding can_manage_cloud_browser_external_links, null
                otherwise (2026-09-16). Each console open used to leave a
                throwaway entry here; minting now sweeps entries that expired
                over 24h ago, so this is the live link list rather than a log.
            vendor_profile_shares:
              type: array
              nullable: true
              items:
                type: object
                properties:
                  email:
                    type: string
                  role:
                    type: string
                  shared_at:
                    type: string
                    nullable: true
                  shared_by:
                    type: string
                    nullable: true
                  vendor_share_id:
                    type: string
                    nullable: true
                required:
                  - email
                  - role
                  - shared_at
                  - shared_by
                  - vendor_share_id
            created_by:
              type: object
              properties:
                actor_type:
                  type: string
                  enum:
                    - user
                    - support
                    - api_key
                    - system
                    - agent
                actor_sid:
                  type: string
                  nullable: true
                team_sid:
                  type: string
                actor_name:
                  type: string
                  nullable: true
                  description: >-
                    The OAuth client that acted ("Claude", "n8n"); null for a
                    user, an API key or a system job.
                oauth_client_sid:
                  type: string
                  nullable: true
                  description: The acting OAuth client (id_oc_*); null off the OAuth path.
                reason:
                  type: string
                  nullable: true
                  description: >-
                    Why a system actor wrote the row (snapshot_capture_job,
                    ...); null otherwise.
                permissions:
                  type: object
                  additionalProperties: {}
                  description: >-
                    Internal audit context: the grant set the actor held at
                    write time. Not a contract.
                cluster_id:
                  type: integer
                  nullable: true
                  description: 'Internal audit context: the cluster that served the write.'
                trace_id:
                  type: string
                  nullable: true
                  description: >-
                    Internal audit context: the trace id of the request that
                    wrote the row.
              required:
                - actor_type
                - actor_sid
                - team_sid
                - permissions
            deleted_by:
              type: object
              nullable: true
              properties:
                actor_type:
                  type: string
                  enum:
                    - user
                    - support
                    - api_key
                    - system
                    - agent
                actor_sid:
                  type: string
                  nullable: true
                team_sid:
                  type: string
                actor_name:
                  type: string
                  nullable: true
                  description: >-
                    The OAuth client that acted ("Claude", "n8n"); null for a
                    user, an API key or a system job.
                oauth_client_sid:
                  type: string
                  nullable: true
                  description: The acting OAuth client (id_oc_*); null off the OAuth path.
                reason:
                  type: string
                  nullable: true
                  description: >-
                    Why a system actor wrote the row (snapshot_capture_job,
                    ...); null otherwise.
                permissions:
                  type: object
                  additionalProperties: {}
                  description: >-
                    Internal audit context: the grant set the actor held at
                    write time. Not a contract.
                cluster_id:
                  type: integer
                  nullable: true
                  description: 'Internal audit context: the cluster that served the write.'
                trace_id:
                  type: string
                  nullable: true
                  description: >-
                    Internal audit context: the trace id of the request that
                    wrote the row.
              required:
                - actor_type
                - actor_sid
                - team_sid
                - permissions
            created_at:
              type: string
            updated_at:
              type: string
            deleted_at:
              type: string
              nullable: true
          required:
            - sid
            - team_sid
            - linkedin_account_sid
            - automation_server_sid
            - account_share_sid
            - share_role
            - vendor_provider
            - vendor_name
            - vendor_profile_id
            - browser_owner
            - status
            - error_reason
            - fail_count
            - last_fail_at
            - logout_count
            - last_logout_at
            - last_start_at
            - last_health_check_at
            - last_activity_at
            - antidetect_browser_proxy_sid
            - proxy_country_code
            - custom_proxy
            - proxy_5g
            - cloud_browser_access
            - vendor_profile_shares
            - created_by
            - deleted_by
            - created_at
            - updated_at
            - deleted_at
        result:
          type: object
          properties:
            access_key:
              type: object
              properties:
                key:
                  type: string
                  nullable: true
                  minLength: 18
                  maxLength: 18
                  pattern: ^cb_ak_
                  description: >-
                    The bearer token itself, in full, for a caller holding
                    can_manage_cloud_browser_external_links (the permission that
                    mints it: reading a key is the same power as minting one,
                    since the public connect checks nothing but the key). null
                    for every other caller; the entry stays so the link, its
                    expiry and its use can still be listed. On
                    cloud-browser-sessions it is masked to the last 4.
                expires_at:
                  type: string
                  nullable: true
                  description: >-
                    ISO 8601 expiry; null means it never expires. Checked at
                    connect and never again, so a session can outlive its own
                    key.
                max_connects:
                  type: number
                  nullable: true
                  description: >-
                    Cap on CONCURRENT sessions on this key; null means
                    unlimited.
                allowed_ips:
                  type: array
                  nullable: true
                  items:
                    type: string
                allowed_countries:
                  type: array
                  nullable: true
                  items:
                    type: string
                purpose:
                  type: string
                  enum:
                    - relogin
                    - recruiter_relogin
                    - share
                  description: >-
                    What the public page behind the link does. Stamped at mint
                    and never re-negotiated at connect, because the visitor is
                    unauthenticated. Absent on keys minted before the field
                    existed, which the backend reads as relogin.
              required:
                - key
                - expires_at
                - max_connects
                - allowed_ips
                - allowed_countries
              description: >-
                The minted entry, key included. Shown once: the key is a bearer
                secret and is never read back in full from any other surface.
            public_connect_url:
              type: string
              description: >-
                Shareable smart link carrying the key. Give this to the person
                who will open it.
            sent_to_email:
              type: string
              description: >-
                Present only when the request carried send_to_email: the address
                the link was mailed to. A queued send, not a delivery receipt.
          required:
            - access_key
            - public_connect_url
        meta:
          type: object
          properties:
            trace_id:
              type: string
              description: UUID v7; same 128-bit value as the X-Trace-Id header.
            span_id:
              type: string
              pattern: ^[0-9a-f]{16}$
              description: 16 hex chars, root span of this request.
            timestamp:
              type: string
              description: ISO 8601 UTC (Y-m-dTH:i:sZ), response time.
            duration_ms:
              type: integer
              minimum: 0
              description: Server-side wall clock.
            team_sid:
              type: string
              nullable: true
              description: >-
                The team this call ran in (the token team, or the team_sid
                override). Null when unauthenticated; absent from pre-2026-08-20
                backends.
            actor_type:
              type: string
              nullable: true
              description: >-
                user | agent | api_key | system. Null when unauthenticated;
                absent from pre-2026-08-20 backends.
          required:
            - trace_id
            - span_id
            - timestamp
            - duration_ms
      required:
        - success
        - operation
        - action
        - item
        - result
        - meta
    McpError:
      type: object
      properties:
        success:
          type: boolean
          enum:
            - false
        error:
          type: object
          properties:
            code:
              type: string
              enum:
                - validation_failed
                - nothing_to_update
                - not_found
                - relation_not_found
                - invalid_transition
                - limit_exceeded
                - payment_required
                - duplicate_rejected
                - conflict
                - delete_blocked
                - unauthorized
                - forbidden
                - rate_limited
                - internal_error
                - service_unavailable
                - not_implemented
            message:
              type: string
            recoverable:
              type: boolean
            suggestion:
              type: string
            field_errors:
              type: object
              additionalProperties:
                type: array
                items:
                  type: object
                  properties:
                    rule:
                      type: string
                    message:
                      type: string
                  required:
                    - rule
                    - message
            blockers:
              type: array
              items:
                type: object
                properties:
                  type:
                    type: string
                    description: >-
                      Machine-readable blocker type (active_flow, pending_tasks,
                      …).
                  severity:
                    type: string
                    enum:
                      - hard
                      - soft
                    description: >-
                      hard = external action required; soft = acknowledge is
                      enough.
                  description:
                    type: string
                  entity_sid:
                    type: string
                    nullable: true
                  count:
                    type: integer
                  resolution:
                    type: string
                    description: 'Hard: tool name to call. Soft: code for acknowledge[].'
                  resolution_hint:
                    type: string
                required:
                  - type
                  - severity
                  - description
                  - entity_sid
                  - resolution
                  - resolution_hint
            context:
              type: object
              additionalProperties: {}
          required:
            - code
            - message
            - recoverable
        meta:
          type: object
          properties:
            trace_id:
              type: string
              description: UUID v7; same 128-bit value as the X-Trace-Id header.
            span_id:
              type: string
              pattern: ^[0-9a-f]{16}$
              description: 16 hex chars, root span of this request.
            timestamp:
              type: string
              description: ISO 8601 UTC (Y-m-dTH:i:sZ), response time.
            duration_ms:
              type: integer
              minimum: 0
              description: Server-side wall clock.
            team_sid:
              type: string
              nullable: true
              description: >-
                The team this call ran in (the token team, or the team_sid
                override). Null when unauthenticated; absent from pre-2026-08-20
                backends.
            actor_type:
              type: string
              nullable: true
              description: >-
                user | agent | api_key | system. Null when unauthenticated;
                absent from pre-2026-08-20 backends.
          required:
            - trace_id
            - span_id
            - timestamp
            - duration_ms
      required:
        - success
        - error
  responses:
    McpClientError:
      description: >-
        MCP error envelope. `error.code` is one of validation_failed,
        nothing_to_update, not_found, relation_not_found, invalid_transition,
        limit_exceeded, payment_required, duplicate_rejected, conflict,
        delete_blocked, unauthorized, forbidden, rate_limited, not_implemented.
      content:
        application/json:
          schema:
            $ref: '#/components/schemas/McpError'
    McpServerError:
      description: >-
        MCP error envelope with `error.code` internal_error or
        service_unavailable.
      content:
        application/json:
          schema:
            $ref: '#/components/schemas/McpError'
  securitySchemes:
    BearerJwt:
      type: http
      scheme: bearer
      bearerFormat: JWT
      description: >-
        Access token issued by gtm.service.id. Its `access_identity` claim
        carries `team_sid`, `actor_sid` and `actor_type`, and that team scope is
        authoritative.
    TeamSid:
      type: apiKey
      in: header
      name: Team-SID
      description: >-
        Team scope for tokens that do not carry one. Ignored when the token
        already names a team.

````

This documentation is built and hosted on [Mintlify](https://mintlify.com), a developer documentation platform.