The documented route is a personal access token pasted into a config. The endpoint also advertises full dynamic client registration, which means a compliant client can authorise itself with nothing to paste — better security, undocumented. Worth trying before falling back to a static token. Undocumented behaviour can change without notice, so treat it as a convenience rather than something to build on.
Kolva's endpoint over their meeting and document workspace. Their documentation describes five capability areas in prose without naming tools.
Semantic search across meeting transcripts, notes, tasks and uploaded documents, plus the other capability areas their documentation describes.
A personal access token as a bearer header, per their documentation. Our probe also found a full OAuth 2.0 flow with PKCE and dynamic client registration, which their docs do not mention.
Paste a URL, then authorize — add the endpoint to your client, then approve the OAuth consent screen