> ## Documentation Index
> Fetch the complete documentation index at: https://docs.autoadify.com/llms.txt
> Use this file to discover all available pages before exploring further.

# Authentication

> API keys, permissions, channel limits and expiry.

Every request to the API and the MCP server carries an API key in the `Authorization` header:

```bash theme={null}
Authorization: Bearer aak_live_...
```

## Creating keys

Create and revoke keys in **Autoadify → Settings → Developers**. You'll be asked to confirm it's you before a key is created.

* The full key is shown **once**, when it's created. Autoadify stores only a hash of it, so it can't show it again. If you lose it, revoke it and create a new one.
* A key acts **as you**: anything it does is recorded as done by you, and it can never do more than your role in the organization allows.
* The API and MCP server are available on paid plans. If your organization moves to the free plan, its keys stop working until it upgrades.

| Plan | Active keys |
| - | - |
| Pro | 3 |
| Team | 15 |
| Enterprise | Unlimited |

## Permissions

Each key has one or more permissions (scopes). Give a key only what it needs.

| Scope | Allows |
| - | - |
| `read` | List channels, posts, media and workflows |
| `publish` | Create, schedule, edit and delete posts; upload, import and delete media |
| `generate` | Generate images and videos, which spends credits (coming soon) |

A request without the right scope gets `403` with the code `forbidden_scope`. On the MCP server, tools a key can't use aren't listed at all.

Viewers can only create `read` keys. If your role changes later, your keys shrink with it within about 30 seconds.

## Limiting a key to some channels

When you create a key you can pick **Only selected** channels. That key then:

* only sees those channels in [List channels](/api-reference/channels/list-channels),
* can only post to them,
* only sees posts that go exclusively to them.

This is a good idea for anything you hand to an automation or an agent.

## Expiry and revocation

Keys can expire after 30 days, 90 days or a year, or never. Revoking a key in Settings → Developers stops it working everywhere within seconds.

<Warning>
  Treat keys like passwords. Never put one in client-side code, a public repository or a shared document.
</Warning>


This documentation is built and hosted on [Mintlify](https://mintlify.com), a developer documentation platform.