# Create and revoke API keys

Give scripts and external AI clients scoped access to one team.

API keys are personal bearer tokens tied to the team selected when you create them. Create and revoke them while signed in through **Settings → Account → API Keys**.

## Create a key

1. Choose **Create key**.
2. Give it a name that identifies its purpose, such as “Reporting export.”
3. Select the intended team.
4. Choose **REST Read only**, **REST Read & Write**, **MCP Read only**, or **MCP Read & Write**.
5. Set an optional expiration date and create the key.
6. Copy the token from **API key created** and store it in your integration's secret configuration.

The plaintext token is shown only once. If you close the dialog without saving it, create a replacement and archive the unused key. MCP keys require a plan other than Free and an available MCP service.

## Understand permissions

Token permissions limit what a client can request. Your current team role and the team's plan still decide whether the action is allowed. A write key cannot give a viewer ordinary work-item editing privileges.

REST and MCP permissions are distinct. Use a REST key for HTTP API endpoints and an MCP key for the MCP connection. Switching teams in the browser or supplying another team ID does not change a token's team.

## Revoke a key

Choose the archive action for the key and confirm **Archive API key**. Archiving keeps the record for audit purposes but immediately prevents authentication with that token. Applications using it lose access, so update them with a replacement first when rotating a working key.

Use **Show archived** to review retained key records. See [REST authentication](https://conversionlab.app/docs/developer/authentication) and [MCP setup](https://conversionlab.app/docs/developer/mcp-setup) for connection examples.
