Cofounder Docs
API Keys and Scripting
Mint API keys for agents and automation, authenticate with COFOUNDER_API_TOKEN, and script the CLI with --json.
Agents, CI jobs, and scripts shouldn't depend on an interactive login.
That's what company API keys and COFOUNDER_API_TOKEN are for.
API keys
| MCP | CLI | API |
|---|---|---|
| — | cofounder company api-keys create | POST /cofounder-cli/v1/company/api-keys |
| — | cofounder company api-keys list | GET /cofounder-cli/v1/company/api-keys |
| — | cofounder company api-keys revoke | DELETE /cofounder-cli/v1/company/api-keys/{key_id} |
Minting credentials isn't on the MCP surface, so create keys from the CLI or API, then hand them to your agent's environment.
cofounder company api-keys create --name deploy-botThe key prints once — store it somewhere safe, because list only ever
shows names and prefixes. A key authenticates as the company it was minted
under.
Use the token
One env var covers the CLI, the API, and MCP clients:
export COFOUNDER_API_TOKEN="cfk_..."
cofounder company show # authenticates as the key's companyFrom a signed-in CLI, cofounder auth token prints a session token for
one-off use. Reach for company API keys for anything durable — they survive
logouts, and you can revoke them independently.
Or skip the CLI and call the API directly:
curl -H "Authorization: Bearer $COFOUNDER_API_TOKEN" \
https://api.superoptimizers.cofounder.co/cofounder-cli/v1/companyScripting
Commands take --json for machine-readable output — stable enough to parse
with jq or feed to another agent:
cofounder company resources list --json | jq '.resources[].status'Interactive commands are the exception: company switch refuses --json
outright, and secrets set needs --stdin for the value in JSON mode.
Non-zero exits still mean failure, so scripts can trust exit codes.
Environment variables
See CLI Environment Variables for the variables the CLI reads.