API keys
Create and manage personal and agent API keys. Where each screen lives, key types, expiry, and how revoking interacts with your organisation's agent-access policy.
Connect your AI agent covers the authentication contract itself. This page is about the two screens where keys get created, listed and revoked.
Where to find them
| Screen | Location | Shows |
|---|---|---|
| Your keys | Account → API Keys | Your own keys, plus creation. |
| Organisation keys | Settings → Organisation Management → API Keys | Every active key in the organisation, including every member's user and agent keys, with admin-only revoke. |
Only an admin sees the organisation-wide screen. Everyone can see and manage their own keys from Account → API Keys.
Key types
- User: acts as you, with your own permissions.
- Agent: scoped automation. An agent key defaults to a safe, read-only baseline. Extra capabilities (vulnerability triage, compliance management, controls and risk) can only be granted if an admin has already enabled them for the organisation, under Organisation Management → Agent Access. Pick an agent key when connecting an MCP client. The MCP server URL is shown alongside it, ready to copy.
Revoking is how you tighten an issued key
Narrowing what agent keys are allowed to do at the organisation level doesn't reach back into keys that already exist. An already-issued key keeps whatever capabilities it was granted. To actually remove a capability from a key in use, revoke it and issue a replacement under the new, narrower policy.
Expiry and revocation
A new key defaults to a 90-day expiry, and can be set out to 365 days. Revoking a key, your own or (as an admin) anyone else's in the organisation, disables it immediately; there's no grace period.