RevDesk
  • Pricing
Product
Features
AI Coworkers
AI coworkers that do the work, not just answer questions.
Omnichannel Messaging
iMessage, WhatsApp, SMS, and email with shared context.
Coaching & Enablement
Coach reps while the call is still happening.
CRM & Desk
A CRM that updates itself and shows what happens next.
Tools
RevDesk API & MCP
Connect your systems and build with RevDesk.
Voice AI
Answer every call and work every lead.
Follow-Up & Reactivation
Follow up until the customer answers.
Desking & Deal OperationsDealerships
Send deals without leaving RevDesk.
Managed PipelineManaged service
RevDesk runs approved outreach for you.
Reporting & Insights
See what is happening across every store.
Solutions
Industries
Automotive
Work every internet lead like your best BDC
HealthcareHIPAA
Patient outreach, intake, and follow-through
Law Firms
Intake, conflict screening, booked consults
B2B SaaS
Speed-to-lead, trials, and partner links
Home Services
Book more jobs from every call and get more customers
Logistics
Cover loads and carriers around the clock
AI Coworkers
Speed-to-Lead
Calls new form leads in seconds
Outbound SDR
Works your lists, warms, books
Customer Care
Reviews, referrals, follow-up care
Re-Engage
Wins back dormant pipeline
ReceptionistIncluded
Answers and routes every call, on every plan
Resources
Blog
Field notes from useful AI
Changelog
What’s new in RevDesk
Developers
RevDesk API, SDK, CLI, webhooks, and MCP
Docs
Platform documentation
Case studies
Stories from leading customers
Trust Center
Security, privacy, and eligible BAAs
Pricing
Sign InBook a Demo
Sign InBook a Demo
RevDesk developers

Least privilege

RevDesk API authentication and OAuth

Authenticate RevDesk API and MCP clients with organization-scoped credentials, named permissions, RFC 9728 protected-resource metadata, and explicit revocation.

What it is

RevDesk production access is organization-scoped. A signed-in organization member creates an API key, selects the smallest named scope set needed by the integration, and stores the credential in the client host's secret manager. RevDesk publishes OAuth authorization-server metadata and RFC 9728 protected-resource metadata so machines can discover the resource, supported bearer method, and available permissions without relying on prose alone.

When to use RevDesk API authentication and OAuth

  • Choose the exact read or write permissions for an API, SDK, CLI, or MCP integration.
  • Recover from a 401, missing-scope 403, expired credential, or revoked key.
  • Build a credential workflow that keeps a person in control of production access.

Recommended workflow

  1. 1Read protected-resource metadata and the OpenAPI operation's security requirement.
  2. 2Create a separate key per agent and environment, selecting only the scopes the task needs.
  3. 3Send the key as an HTTP Bearer credential, rotate it deliberately, and revoke it immediately when access is no longer required.

Safety and approval boundaries

  • RevDesk does not currently advertise anonymous agent credential claims or dynamic client registration for v1 API keys.
  • A credential must never be placed in a prompt, browser URL, source file, or public log.
  • Possessing a write scope does not replace user approval for costly or externally visible actions.

Official RevDesk resources

RevDesk authentication guideMachine-readable registration, use, error recovery, and revocation walkthrough.Protected-resource metadataRFC 9728 API resource identifier, authorization servers, and supported scopes.Authorization-server metadataMachine-readable OAuth server capabilities.Authentication documentationHuman-readable credential setup and request examples.

Canonical page: https://www.revdesk.com/developers/auth

RevDesk
Product
AI CoworkersOmnichannel MessagingCRM & DeskCoaching & EnablementReporting & InsightsVoice AIFollow-Up & ReactivationPricingBook a Demo
Solutions
For AutomotiveFor HealthcareFor Law FirmsFor B2B SaaSFor Home ServicesFor Logistics
Resources
BlogDevelopersDocumentationChangelogRoadmapSMS SubscribeCase StudiesAffiliate
Company
AboutCareersPartnersBrandContactSecurityTrustStatus

Ask your AI assistant about RevDesk

revdesk.com/llms.txt
© RevDesk™ 2026 · Cell Labs, Inc.Privacy Policy·Terms of Service·Acceptable Use·Sub-processorsRevDesk™ is a trademark of Cell Labs, Inc. All other marks are property of their respective owners.