Back to site

API keys

Settings → API Keys shows two different kinds of credentials. They cannot be used in place of each other.

CredentialDirectionManage it here
Portal/MCP keyExternal assistant → your portal records and toolsCreate or revoke in API Keys; connect in MCP Server
Provider API keyYour portal → cloud AI serviceAI Models & Chat
Gateway tokenYour portal → self-hosted AI gatewaySelf-Hosted AI

A saved or selected credential is not proof that its connection or model has passed a response test.

Create an MCP key

An account owner can use Create MCP key. Give it a recognizable label, review the included access, and select only the needed action groups:

  • Time tracking
  • Clients
  • Projects
  • Billing & comms
  • Calendar
  • Settings
  • Team

The current creation form issues admin-scoped keys, not client login credentials. Included reads cover organization business information such as clients, insights, activity, and curated settings. Some catalog operations can change state without an optional write group; review that disclosure on the form and the MCP tool catalog.

Copy the full ctsp_live_ key from the newly created-key banner and store it securely. The stored key record uses a hash; the list shows a prefix rather than a way to reveal an existing secret. Create a replacement if you lose it.

What controls access?

The bearer key, its scope and permissions, active/expiry state, any configured IP restriction, its creator's current owner authority, and the organization's MCP setting all matter. Individual tools also apply record and workflow checks.

Keys do not depend on an open browser session. Signing out of Clerk does not revoke a key. Owner-managed key access is separate from a client accepting portal or SMS terms.

Use MCP Server to enable the connection, copy the endpoint/client setup, browse tools, and test it. The MCP guide explains approval tokens and interrupted-action recovery.

Revoke or replace a key

Revoke a key you no longer use or believe was exposed. To change the action permissions offered by the current creation flow, create a replacement with the desired groups, update the assistant's configuration, and revoke the old one.

The list reports status, expiry when present, and last use. Do not interpret “no recent use” as proof a secret was never copied. Disabling MCP blocks that feature while disabled; exposed keys should still be revoked.

Provider credentials

The outbound section shows configured providers, their model, masked key metadata, and which service is selected. Manage opens the matching cloud or self-hosted page.

Cloud providers retain separate key/model slots. A blank field keeps the saved key for that provider. Unknown-ownership legacy credentials can be quarantined and require explicit re-entry before use. See AI models and chat for model tests, saving, and usage.