Authentication
The CannMenus API uses API tokens for authentication. Include your token in every request to access the API.
Getting Your API Token
- Log in to your CannMenus Pro account
- Navigate to the API section in your dashboard
- Click Generate Token to create a new token
You can have up to two active tokens at any time. This allows for seamless token rotation without downtime.
Using Your Token
Include your API token in the X-Token header of every request:
curl "https://api.cannmenus.com/v2/products?states=California&page=1" \
-H "X-Token: YOUR_API_TOKEN"
Python
import requests
headers = {"X-Token": "YOUR_API_TOKEN"}
response = requests.get(
"https://api.cannmenus.com/v2/products",
headers=headers,
params={"states": "California", "page": 1}
)
JavaScript
const response = await fetch(
"https://api.cannmenus.com/v2/products?states=California&page=1",
{
headers: { "X-Token": "YOUR_API_TOKEN" }
}
);
OAuth Authentication (MCP)
Claude.ai and other OAuth-compatible clients can authenticate with the CannMenus MCP server via OAuth 2.0 authorization code flow — no API token needed.
When using OAuth:
- You are redirected to cannmenus.com to log in and approve access
- Access is tied to your user's organization — no separate API token is required
- Data access is scoped to the organization's configured permissions (states, brands, dispensaries)
This is the recommended authentication method for Claude.ai. See MCP Setup for configuration details.
OAuth is only available for the MCP server. The REST API continues to use token-based authentication via the X-Token header.
Data Access Scope
Your plan includes a specific set of states.
- Use full state names (
New Jersey, notNJ) instatesandstateparameters and in MCP tool arguments. - To see which states your key covers, call the
whoamitool on the MCP server. Itscovered_statesfield lists your plan's states, or"all"for full-access plans.
Token Management Best Practices
Use Separate Tokens for Each Environment
Keep development and production tokens separate. If a development token is compromised, your production integration remains secure.
Rotate Tokens Regularly
- Generate a new token in the dashboard
- Update your application to use the new token
- Verify the new token works
- Delete the old token
With two active tokens, you can rotate without any downtime.
Keep Tokens Secure
- Never commit tokens to version control — Use environment variables
- Never expose tokens in client-side code — Make API calls from your backend
- Never share tokens — Each integration should use its own token
# Store in environment variable
export CANNMENUS_API_TOKEN="your_token_here"
import os
token = os.environ.get("CANNMENUS_API_TOKEN")
Authentication Errors
| Status Code | Description |
|---|---|
403 | No API token was sent |
404 | Invalid or expired API token |
Example Error Responses
When no token is sent, the API returns a 403 status:
{
"detail": "Missing API token. Send it as 'X-Token: <token>' or 'Authorization: Bearer <token>'."
}
When an invalid or expired token is sent, the API returns a 404 status:
{
"detail": "Invalid or expired token"
}
Troubleshooting
- Check the header — Send your token as
X-Token: YOUR_API_TOKEN - Verify the token value — Copy directly from the dashboard, no extra spaces
- Confirm the token is active — Check the dashboard to ensure it wasn't deleted
- Check your plan's states — Your key covers the states in your plan; see Data Access Scope
Need Help?
If you're having authentication issues, contact support with:
- The error message you're receiving
- The endpoint you're trying to access
- When the issue started (especially if it was working before)
