MCP

API Keys

Keys let an MCP client or your own code act in your workspace. Each one has scopes and can expire.

Creating a key

  1. Open Settings → API keys
    From the settings menu.
  2. Name it and pick its scopes
    Name it after where it will be used — “Claude on my laptop”, “CI”.
  3. Set an expiry
    Optional unless your workspace requires one. A key that expires stops being a risk on its own if it leaks.
  4. Copy it
    Keys look like wf_live_… and are shown only once. Store it like a password.

Scopes

ScopeAllowsTools
readReading projects, skills and credits, and checking specificationslist_projects, get_project, list_skills, get_credits, validate_spec
writeBuilding new projects — this spends creditscreate_site
publishPutting projects live on the internetpublish_site

A client only sees the tools its key’s scopes allow. Give each key the least it needs — an assistant that only reports on projects needs just read.

Looking after keys

  • Keys are stored hashed. Webforgia can show you a key’s prefix and when it was last used, never the key itself.
  • Revoke a key from Settings → API keys. Its creator, or a workspace owner or admin, can revoke it.
  • Creating and revoking keys is recorded in the workspace audit log.
  • Owners and admins can require expiry dates, cap how long a key may live, and forbid keys that can publish, in the Security center policy.