API keys (TenancyEngine)
Create and revoke organization-scoped developer keys for MCP integrations, automation, and device-code approval flows.
Console: TenancyEngine console → API keys (/api-keys)
Who can use this page
Organization-scoped vendor admins manage keys for their vendor organization. Platform operators with broader access still pick an organization when multiple orgs are linked to their login.
Create a key
- Select the target organization (when more than one is available).
- Enter a descriptive name and optional scopes (for example
mcp.full). - Optionally set an expiry date.
- Click Create key — the plaintext key is shown once. Copy it immediately; it cannot be retrieved later.
Device code approval
When an MCP client shows a user code, paste it on this page to approve a scoped key without exposing long-lived credentials in chat.
Revoke a key
Use Revoke on an active key to disable it immediately. Revoked keys fail authentication on the next API call.