Skip to main content
An API key (aik_…) authenticates a script, CI job, or MCP client as you — no browser session needed. It acts with your own permissions: whatever you can see and do in the app, a key you create can too.

Create one

Go to app.atako.ai → Settings → API keys (admin-only) and click Create key. Pick its scope and expiry (see below). The full key is shown once — copy it immediately and store it somewhere safe (a password manager or secrets store, not a shared doc). See Settings → API keys for the click-through steps.

Use it

Pass the key as a Bearer token on any authenticated Atako API request:
This is the same header the Atako MCP server uses — see its quickstart for ready-to-paste configs for Claude Code, Claude Desktop, Cursor, and ChatGPT developer mode.

Security

  • Treat a key like a password — anyone who has it can act as you.
  • Revoke a key from Settings → API keys the moment you stop using it (e.g. you rotate a script, or a laptop with a key in its config is lost). Revoking is immediate and can’t be undone.
  • Give each script its own key, named after what it does, so you can revoke one without breaking the others.

Scope

Some operations are refused to every key (403 API_KEY_FORBIDDEN) and need you signed in to the app: billing changes (plan, seats, payment, credits), creating, revoking or deleting API keys, deleting your account, and minting an agent token. The API reference marks each operation with x-atako-api-key: read | write | forbidden. The scope and expiry are set when the key is created; to change them, create a new key and revoke the old one.

Expiry

A key can expire after 30, 90 or 365 days, or never. Past that date it is refused with 401 API_KEY_EXPIRED, exactly like a revoked key.