scrollport keeps three authentication planes separate.

## Human plane

The web app uses the human session for wallet, connections and other account surfaces. Anonymous visitors are sent through the app's sign-in flow before protected pages render.

## Agent plane

The device flow issues an API key bound to an account and the fixed scopes `discover`, `inspect`, `run` and `wallet`. Keys are hashed at rest. MCP uses the same bearer key; MCP is a transport, not a separate signup system.

```http
Authorization: Bearer sp_live_<secret>
```

`sys-admin` is not requestable through device authorization. It is an operator scope, not a customer or agent grant.

## Provider plane

Provider connections are keyed by account. The run layer resolves the account to a connection and a provider proxy; raw provider tokens do not enter the agent's context.

## Safe handling

Treat a key as a secret with account-wide spending authority. Store it in a secret manager, rotate it by issue → verify → revoke, and never include it in a URL, screenshot or support message.

See [headless setup](https://scrollport.com/docs/setup/headless) for the device endpoints and [transports](https://scrollport.com/docs/reference/transports) for how the same contract travels over HTTP and MCP.