Skip to main content
A credential acts as its AutoAdy identity. It does not create a separate service account or bypass that identity’s permissions, plan, or tool limits.

Create a key

  1. Sign in with the identity that should make the calls.
  2. Open AutoAdy API keys under Settings → AI & Agents.
  3. Enter a Key name that identifies the client or job.
  4. Choose Expires: Never, In 30 days, In 90 days, or In 1 year. Never is the default.
  5. Select Generate Key and copy the full adk_ key immediately. It is shown only at creation.
  6. Store it in a private runtime environment or secret store. Verify access with list-accounts.
You can have three unrevoked manual keys. Expired keys still occupy a slot until revoked. If the limit is reached, revoke an unused key before creating another. Losing a key requires replacement; the list shows its prefix and metadata, not the original secret.

Send a REST credential

Use this header on POST https://www.autoady.io/api/mcp/{tool}. REST does not authenticate from a query parameter, browser cookie, or Basic Auth. Keep keys out of client-side code, repositories, URLs, screenshots, and support messages.

Understand account and write access

There is no per-key account scope or selectable read-only scope. Owners can target their connected, plan-eligible accounts; workspace members remain subject to their account grants and role. A selected account is a default for calls that omit account_id, not a security boundary. Send an explicit account ID for unattended jobs. Client Viewer access cannot perform writes. Plan and tool gates apply separately: creating a key does not unlock paid generation, provider writes, or unavailable integrations. Free-plan access includes reads and the library-only save-creative exception; other writes require eligible access. Model-backed tools may have a daily allowance in addition to the request limit. Inspect the returned refusal and current plan rather than assuming every read has identical entitlement. For an external agent, configure its own tool allowlist and approval policy. Those controls supplement AutoAdy’s server checks. They do not turn the underlying credential into a scoped key.

Use OAuth for a remote MCP client

Clients that implement MCP authorization can sign in and approve AutoAdy through OAuth 2.1. Use the remote MCP endpoint; a manual key is not needed for that flow. OAuth connections have a separate limit of ten and appear under Connected apps. Reauthorizing the same client replaces its existing connection. They do not consume the three manual-key slots.

Replace or revoke access

For a manual-key rotation, create a replacement, update the client’s private credential, verify a read, then Revoke the old key. If the old key is exposed, revoke it immediately and replace it before resuming the client. Revoke an OAuth row under Connected apps to disconnect that client. Expired, revoked, malformed, or missing keys return HTTP 401; replace the key or reconnect OAuth with the intended identity. A 403 is a permission or plan refusal, so replacing a valid credential will not resolve it.