Where to find it
API Keys.
How to use it
- Create a named key for one integration and copy the secret when displayed.
- Choose the required read/write baseline and module scopes instead of broad access where possible.
- Restrict channel access, set expiry and enable signed requests if your integration supports the required signature headers.
- Review usage and revoke unused keys. Update the consuming integration when rotating its credentials.
Permissions and important details
API keys and MCP tokens are separate credentials and are not interchangeable. Keep both out of messages, URLs and source control. Channel-restricted API operations may require an explicit channel ID.