Create and revoke API keys
Give scripts and external AI clients scoped access to one team.
API keys are personal bearer tokens tied to the team selected when you create them. Create and revoke them while signed in through Settings → Account → API Keys.
Create a key
- Choose Create key.
- Give it a name that identifies its purpose, such as “Reporting export.”
- Select the intended team.
- Choose REST Read only, REST Read & Write, MCP Read only, or MCP Read & Write.
- Set an optional expiration date and create the key.
- Copy the token from API key created and store it in your integration's secret configuration.
The plaintext token is shown only once. If you close the dialog without saving it, create a replacement and archive the unused key. MCP keys require a plan other than Free and an available MCP service.
Understand permissions
Token permissions limit what a client can request. Your current team role and the team's plan still decide whether the action is allowed. A write key cannot give a viewer ordinary work-item editing privileges.
REST and MCP permissions are distinct. Use a REST key for HTTP API endpoints and an MCP key for the MCP connection. Switching teams in the browser or supplying another team ID does not change a token's team.
Revoke a key
Choose the archive action for the key and confirm Archive API key. Archiving keeps the record for audit purposes but immediately prevents authentication with that token. Applications using it lose access, so update them with a replacement first when rotating a working key.
Use Show archived to review retained key records. See REST authentication and MCP setup for connection examples.