Skip to main content
Go to Settings → MCP, under Integrations.
The create API key dialog showing key name, brand access, and the permission checkboxes with the first four ticked

Creating a key

1

Click Create API key

Give it a name you’ll recognise later — the client it’s for, or the person using it.
2

Choose the brand access

Pick a single brand, or All brands — which creates one key with full access to every brand in the workspace.
3

Tick the permissions

Context, Content knowledge, Analytics and Drafts are on by default. Publishing (marked high risk), Draft media, Knowledge writes and the two workspace-wide reads are opt-in.
4

Copy the connection URL

This is the only time you’ll see it.
The API key created dialog, confirming the key was made and offering the connection URL and the raw API key, each with a copy button
You get two things. The connection URL is the one you want — it’s what almost every client asks for, and the key is already inside it. The API key on its own is only for clients that want an Authorization header instead.
The full connection URL is shown once, at creation. If you lose it, you can’t recover it — delete the key and create a new one.

Brand key or workspace key

Brand key

Scoped to one brand. The client acts on that brand and sees nothing else. Right for most people, and for anyone working on a single client.

All brands

Full access to every brand in the workspace, plus the cross-brand analytics and calendar tools. Workspace analytics is admins only. For someone reporting across clients.
With a workspace key, anything that writes still needs the brand named explicitly — so a client can’t save a draft to the wrong brand by accident.

Managing keys

The MCP settings page listing API keys with their access, permissions and last used date
The keys table shows each key’s name, access, permissions, when it was last used, and when it was created. Last used is the one to check periodically — a key that’s never been used is either a failed setup or one worth deleting. Delete revokes a key immediately. Any client using it stops working at once, so it’s the right response to a URL you think has leaked.

Choosing permissions well

Drafting is reversible; publishing to LinkedIn isn’t — and the dialog marks it high risk for that reason. Run without it for a while and add it once you trust the setup.
Separate keys can be revoked separately. A single shared key means revoking it breaks everyone.
A brand key is a smaller blast radius. Reach for the workspace key when you actually want reporting across brands.

Connect Claude or ChatGPT

What to do with the URL you just copied.

What the connector does

Permissions and capabilities in full.