> ## Documentation Index
> Fetch the complete documentation index at: https://help.autoady.io/llms.txt
> Use this file to discover all available pages before exploring further.

# Authenticate and manage access

> Create, store, replace, and revoke API keys or OAuth connections.

A credential acts as its AutoAdy identity. It does not create a separate service account or bypass that identity's permissions, plan, or tool limits.

## Create a key

1. Sign in with the identity that should make the calls.
2. Open [AutoAdy API keys](https://app.autoady.io/settings?tab=api-keys) under **Settings → AI & Agents**.
3. Enter a **Key name** that identifies the client or job.
4. Choose **Expires**: **Never**, **In 30 days**, **In 90 days**, or **In 1 year**. **Never** is the default.
5. Select **Generate Key** and copy the full `adk_` key immediately. It is shown only at creation.
6. Store it in a private runtime environment or secret store. Verify access with [list-accounts](/developers/overview#quickstart).

You can have three unrevoked manual keys. Expired keys still occupy a slot until revoked. If the limit is reached, revoke an unused key before creating another. Losing a key requires replacement; the list shows its prefix and metadata, not the original secret.

## Send a REST credential

```http theme={null}
Authorization: Bearer adk_YOUR_KEY
Content-Type: application/json
```

Use this header on `POST https://www.autoady.io/api/mcp/{tool}`. REST does not authenticate from a query parameter, browser cookie, or Basic Auth. Keep keys out of client-side code, repositories, URLs, screenshots, and support messages.

## Understand account and write access

There is no per-key account scope or selectable read-only scope. Owners can target their connected, plan-eligible accounts; workspace members remain subject to their account grants and role. A selected account is a default for calls that omit `account_id`, not a security boundary. Send an explicit account ID for unattended jobs.

Client Viewer access cannot perform writes. Plan and tool gates apply separately: creating a key does not unlock paid generation, provider writes, or unavailable integrations. Free-plan access includes reads and the library-only `save-creative` exception; other writes require eligible access. Model-backed tools may have a daily allowance in addition to the request limit. Inspect the returned refusal and current plan rather than assuming every read has identical entitlement.

For an external agent, configure its own tool allowlist and approval policy. Those controls supplement AutoAdy's server checks. They do not turn the underlying credential into a scoped key.

## Use OAuth for a remote MCP client

Clients that implement MCP authorization can sign in and approve AutoAdy through OAuth 2.1. Use [the remote MCP endpoint](/developers/clients#mcp-server); a manual key is not needed for that flow.

OAuth connections have a separate limit of ten and appear under **Connected apps**. Reauthorizing the same client replaces its existing connection. They do not consume the three manual-key slots.

## Replace or revoke access

For a manual-key rotation, create a replacement, update the client's private credential, verify a read, then **Revoke** the old key. If the old key is exposed, revoke it immediately and replace it before resuming the client.

Revoke an OAuth row under **Connected apps** to disconnect that client. Expired, revoked, malformed, or missing keys return HTTP 401; replace the key or reconnect OAuth with the intended identity. A 403 is a permission or plan refusal, so replacing a valid credential will not resolve it.


This documentation is built and hosted on [Mintlify](https://mintlify.com), a developer documentation platform.