> For the complete documentation index, see [llms.txt](https://help.zaapi.com/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://help.zaapi.com/developers/authentication.md).

# Authentication

An API key is a secret credential that lets something outside Zaapi act on your workspace, such as the Zaapi [Open API](/developers/open-api.md) or [MCP](/developers/mcp.md).

### Create an API key

Go to **Settings → Developers → API Keys** in the Zaapi app.

1. Click **Add API key**.
2. Give it a name — use something that identifies what it's for, like `Claude Desktop` or `Support automation`.
3. Choose the scopes the key should have. These control what your assistant can reach: read scopes let it look things up, write scopes let it make changes. Grant only what you need — a read-only key can't send a message to a customer or close a ticket by mistake.
4. Click create, then **copy the key immediately**.

> **The key is shown once.** You won't be able to see it again after you close the dialog, so paste it somewhere safe before continuing. If you lose it, rotate the key to get a new one.

**Keys expire after 6 months.** You'll need to rotate the key and update your config before then.

### Managing keys

* **Rotate** issues a new secret while keeping the key's name and permissions. The old secret keeps working for two hours, so you have time to deploy the new one. The 6-month expiry restarts from the day you rotate.
* **Edit** renames a key or changes its scopes. The secret itself doesn't change, so nothing using it needs updating.
* **Delete** takes effect immediately and can't be undone — any request using that key starts failing straight away.

### Security

* **Treat the API key like a password.** Anyone with it has the permissions you granted, against your live workspace.
* **Don't commit it.** Keep it out of git — if you use a project-level config file like `.cursor/mcp.json`, add it to `.gitignore`.
* **Grant the minimum scopes.** Start read-only and add write access only when you need it.
* **One key per person or service.** That way you can rotate or delete one without disrupting everyone.
* **Delete keys you're no longer using**, including when someone leaves the team.
