K

kennel REST API

REST detected 2026-08-28

Details
URL
https://kennel.work/api/v1
Spec
https://kennel.work/openapi.json
Docs
https://kennel.work/docs
Authentication
kennel API key api_key discovered Get key ↗

Sign in on kennel and create a key on the API keys page. Keys are prefixed kn_, shown once, and grant full read/write access to tasks, labels, and projects. Send the key as Authorization: Bearer kn_...; owner-declared metadata also says x-api-key: kn_... is accepted.

OAuth 2.0 oauth2 discovered
OAuth 2.0 — self-onboarding

Point your MCP client at the server URL and approve access in the browser. The server supports OAuth Dynamic Client Registration (RFC 7591), so the client registers itself automatically — no developer-portal app, client_id, or client_secret to create.

kennel API key api_key declared Get key ↗
Authorization: Bearer <credential> /x-api-key: <credential>

Sign in at https://kennel.work and create a key on the API keys page.

Keys are prefixed kn_ and are shown once, so copy the value when it is created. Every key carries both tasks:read and tasks:write; there is no way to scope one down, so use OAuth when a client should hold narrower or shorter-lived access.

Send it either as Authorization: Bearer kn_... or as x-api-key: kn_....

kennel OAuth 2.1 access token oauth2 declared Set up OAuth ↗
Authorization: Bearer <credential>

Register a client on the OAuth page, or let the client register itself through dynamic client registration at https://kennel.work/api/auth/oauth2/register.

Run the authorization code flow with PKCE against the issuer https://kennel.work/api/auth; its metadata lives at https://kennel.work/.well-known/oauth-authorization-server/api/auth. Request tasks:read, tasks:write, or both.

Clients that cannot open a browser redirect can use the device authorization grant: POST https://kennel.work/api/auth/device/code, send the user to https://kennel.work/device with the user code, then poll https://kennel.work/api/auth/oauth2/token with grant_type=urn:ietf:params:oauth:grant-type:device_code.

Send the resulting access token as Authorization: Bearer <token>. Users can revoke authorized apps from the same page.