Create and manage access keys

Documentation/Teams and access

Create and manage access keys

Give external clients dedicated access, scope it to their tasks, and revoke it when no longer needed.

Updated 2 min read
On this page

When a key is needed

The browser workspace and built-in Chat use account sign-in. External MCP clients and key-based controllers use workspace-issued mk_ keys. These identities are not interchangeable.

Open MCP management. If you cannot access it, ask your workspace administrator to check your role and integration access.

Create dedicated access

  1. Create a key with a recognizable purpose, such as “AI client on office laptop”.
  2. Choose an expiry and review the selected tool permissions. Remove permissions the task does not need.
  3. For device discovery, select devices.list; add device.read for system information. Add desktop, file and terminal permissions separately as needed.
  4. Save the complete key immediately after creation. It is shown only once; use your client's credential storage or an environment variable.

The key belongs to the workspace where it was created and remains subject to member and group access. Selecting a capability does not grant access to another workspace's devices.

Configure client identity

Store the key in a trusted local or server-side client. Keep it out of frontend code, URLs, public repositories and screenshots. Use one key per purpose so you can disable them independently.

Require local Agent identity is for clients that can send the prescribed identity headers. Enabling it for a generic MCP client without that support can cause authentication failures. Client source records help identify changes; they are not a guarantee of hardware identity.

Review sources and revoke

Open a key's client records to review first and last use, platform, risk signals and status. Check unexpected sources against your own devices. Blocking a source limits that source; if the complete key may be exposed, revoke the key and create a replacement.

New authentication requests are rejected after revocation. Separately confirm ongoing tasks have stopped and sessions have closed. Reconnect after replacing a key and check that the discovered tools match the intended permissions.

Need a hand?

Include the issue and the steps you took so it is easier to investigate.

Contact support