MCP
API Keys
Keys let an MCP client or your own code act in your workspace. Each one has scopes and can expire.
Creating a key
- Open Settings → API keysFrom the settings menu.
- Name it and pick its scopesName it after where it will be used — “Claude on my laptop”, “CI”.
- Set an expiryOptional unless your workspace requires one. A key that expires stops being a risk on its own if it leaks.
- Copy itKeys look like
wf_live_…and are shown only once. Store it like a password.
Scopes
| Scope | Allows | Tools |
|---|---|---|
read | Reading projects, skills and credits, and checking specifications | list_projects, get_project, list_skills, get_credits, validate_spec |
write | Building new projects — this spends credits | create_site |
publish | Putting projects live on the internet | publish_site |
A client only sees the tools its key’s scopes allow. Give each key the least it needs — an assistant that only reports on projects needs just read.
Looking after keys
- Keys are stored hashed. Webforgia can show you a key’s prefix and when it was last used, never the key itself.
- Revoke a key from Settings → API keys. Its creator, or a workspace owner or admin, can revoke it.
- Creating and revoking keys is recorded in the workspace audit log.
- Owners and admins can require expiry dates, cap how long a key may live, and forbid keys that can publish, in the Security center policy.