Create a key
- Sign in with the identity that should make the calls.
- Open AutoAdy API keys under Settings → AI & Agents.
- Enter a Key name that identifies the client or job.
- Choose Expires: Never, In 30 days, In 90 days, or In 1 year. Never is the default.
- Select Generate Key and copy the full
adk_key immediately. It is shown only at creation. - Store it in a private runtime environment or secret store. Verify access with list-accounts.
Send a REST credential
POST https://www.autoady.io/api/mcp/{tool}. REST does not authenticate from a query parameter, browser cookie, or Basic Auth. Keep keys out of client-side code, repositories, URLs, screenshots, and support messages.
Understand account and write access
There is no per-key account scope or selectable read-only scope. Owners can target their connected, plan-eligible accounts; workspace members remain subject to their account grants and role. A selected account is a default for calls that omitaccount_id, not a security boundary. Send an explicit account ID for unattended jobs.
Client Viewer access cannot perform writes. Plan and tool gates apply separately: creating a key does not unlock paid generation, provider writes, or unavailable integrations. Free-plan access includes reads and the library-only save-creative exception; other writes require eligible access. Model-backed tools may have a daily allowance in addition to the request limit. Inspect the returned refusal and current plan rather than assuming every read has identical entitlement.
For an external agent, configure its own tool allowlist and approval policy. Those controls supplement AutoAdy’s server checks. They do not turn the underlying credential into a scoped key.