Skip to main content

Personal keys

Open My API Keys from the profile menu. Select Create API key, enter a name, choose an expiry and select Read-only, Edit or Administrative permissions. A key’s effective permission is capped by your current workspace role. The secret is shown when created. Copy it to your client’s protected environment and close the dialog. Rootset does not show it again in the key list. Revoke a key when it is no longer needed; rotate a key to replace its secret and update the clients using it.

Team keys

Admins manage Team Settings → API Keys. Team keys are workspace-owned credentials for automation with the same three permission levels. Creation, rotation and revocation are Admin actions.

Use a key

Use the public API origin for REST and MCP. Do not put keys into URLs, documentation screenshots, browser bundles or Git. Authentication still checks expiration, revocation and current authority on each request.