> ## Documentation Index
> Fetch the complete documentation index at: https://docs.atako.ai/llms.txt
> Use this file to discover all available pages before exploring further.

# API keys

> Create a programmatic API key to authenticate scripts, CI, and MCP clients.

An API key (`aik_…`) authenticates a script, CI job, or MCP client as you — no
browser session needed. It acts with your own permissions: whatever you can see
and do in the app, a key you create can too.

## Create one

Go to [app.atako.ai](https://app.atako.ai) → **Settings → API keys** (admin-only)
and click **Create key**. Pick its **scope** and **expiry** (see below). The full key is shown **once** — copy it immediately and
store it somewhere safe (a password manager or secrets store, not a shared doc).
See [Settings → API keys](/guides/settings#api-keys) for the click-through steps.

## Use it

Pass the key as a Bearer token on any authenticated Atako API request:

```bash theme={null}
curl https://api.atako.ai/agents \
  -H "Authorization: Bearer aik_..."
```

This is the same header the [Atako MCP server](/developers/mcp/overview) uses — see
its [quickstart](/developers/mcp/quickstart) for ready-to-paste configs for Claude
Code, Claude Desktop, Cursor, and ChatGPT developer mode.

## Security

* Treat a key like a password — anyone who has it can act as you.
* Revoke a key from **Settings → API keys** the moment you stop using it (e.g. you
  rotate a script, or a laptop with a key in its config is lost). Revoking is
  immediate and can't be undone.
* Give each script its own key, named after what it does, so you can revoke one
  without breaking the others.

## Scope

| Scope | What the key can do |
| - | - |
| **Read** | `GET` requests only — any other verb returns `403 API_KEY_READ_ONLY`. Over MCP, only read-only tools are listed. |
| **Read & write** | Everything you can do in the app, except the operations below. |

Some operations are refused to **every** key (`403 API_KEY_FORBIDDEN`) and need you
signed in to the app: billing changes (plan, seats, payment, credits), creating,
revoking or deleting API keys, deleting your account, and minting an agent token.
The [API reference](/api-reference/openapi.json) marks each operation with
`x-atako-api-key: read | write | forbidden`.

The scope and expiry are set when the key is created; to change them, create a new
key and revoke the old one.

## Expiry

A key can expire after 30, 90 or 365 days, or never. Past that date it is refused
with `401 API_KEY_EXPIRED`, exactly like a revoked key.


This documentation is built and hosted on [Mintlify](https://mintlify.com), a developer documentation platform.