API keys
Settings → API Keys shows two different kinds of credentials. They cannot be used in place of each other.
| Credential | Direction | Manage it here |
|---|---|---|
| Portal/MCP key | External assistant → your portal records and tools | Create or revoke in API Keys; connect in MCP Server |
| Provider API key | Your portal → cloud AI service | AI Models & Chat |
| Gateway token | Your portal → self-hosted AI gateway | Self-Hosted AI |
A saved or selected credential is not proof that its connection or model has passed a response test.
Create an MCP key
An account owner can use Create MCP key. Give it a recognizable label, review the included access, and select only the needed action groups:
- Time tracking
- Clients
- Projects
- Billing & comms
- Calendar
- Settings
- Team
The current creation form issues admin-scoped keys, not client login credentials. Included reads cover organization business information such as clients, insights, activity, and curated settings. Some catalog operations can change state without an optional write group; review that disclosure on the form and the MCP tool catalog.
Copy the full ctsp_live_ key from the newly created-key banner and store it securely. The stored key record uses a hash; the list shows a prefix rather than a way to reveal an existing secret. Create a replacement if you lose it.
What controls access?
The bearer key, its scope and permissions, active/expiry state, any configured IP restriction, its creator's current owner authority, and the organization's MCP setting all matter. Individual tools also apply record and workflow checks.
Keys do not depend on an open browser session. Signing out of Clerk does not revoke a key. Owner-managed key access is separate from a client accepting portal or SMS terms.
Use MCP Server to enable the connection, copy the endpoint/client setup, browse tools, and test it. The MCP guide explains approval tokens and interrupted-action recovery.
Revoke or replace a key
Revoke a key you no longer use or believe was exposed. To change the action permissions offered by the current creation flow, create a replacement with the desired groups, update the assistant's configuration, and revoke the old one.
The list reports status, expiry when present, and last use. Do not interpret “no recent use” as proof a secret was never copied. Disabling MCP blocks that feature while disabled; exposed keys should still be revoked.
Provider credentials
The outbound section shows configured providers, their model, masked key metadata, and which service is selected. Manage opens the matching cloud or self-hosted page.
Cloud providers retain separate key/model slots. A blank field keeps the saved key for that provider. Unknown-ownership legacy credentials can be quarantined and require explicit re-entry before use. See AI models and chat for model tests, saving, and usage.
