Docs
Using AI

API keys

Create and manage personal and agent API keys. Where each screen lives, key types, expiry, and how revoking interacts with your organisation's agent-access policy.

Connect your AI agent covers the authentication contract itself. This page is about the two screens where keys get created, listed and revoked.

Where to find them

ScreenLocationShows
Your keysAccount → API KeysYour own keys, plus creation.
Organisation keysSettings → Organisation Management → API KeysEvery active key in the organisation, including every member's user and agent keys, with admin-only revoke.

Only an admin sees the organisation-wide screen. Everyone can see and manage their own keys from Account → API Keys.

Key types

  • User: acts as you, with your own permissions.
  • Agent: scoped automation. An agent key defaults to a safe, read-only baseline. Extra capabilities (vulnerability triage, compliance management, controls and risk) can only be granted if an admin has already enabled them for the organisation, under Organisation Management → Agent Access. Pick an agent key when connecting an MCP client. The MCP server URL is shown alongside it, ready to copy.

Revoking is how you tighten an issued key

Narrowing what agent keys are allowed to do at the organisation level doesn't reach back into keys that already exist. An already-issued key keeps whatever capabilities it was granted. To actually remove a capability from a key in use, revoke it and issue a replacement under the new, narrower policy.

Expiry and revocation

A new key defaults to a 90-day expiry, and can be set out to 365 days. Revoking a key, your own or (as an admin) anyone else's in the organisation, disables it immediately; there's no grace period.

Next steps

On this page