Managing API Keys

An API key lets another system, or an AI assistant, act on your Manifestly account. Keys are created and revoked in Settings → Integrations, under API Keys. You need to be a master admin.

Create a key

  1. Go to Settings → Integrations and find the API Keys section.
  2. Click New API Key.
  3. Give it a descriptive name, such as "Zapier integration" or "Claude MCP", and save.
  4. Use Copy to copy the key value.

Name keys after what uses them, not after who made them. When you come to revoke one in a year's time, "Zapier integration" tells you what will break and "Steve's key" does not.

Keys and MCP

This catches people out. Only keys in the current mf_1_ format work with the MCP server. Older 32-character keys still work with the REST API, but the MCP server rejects them, so connecting an AI assistant with one fails to authenticate.

An eligible key shows an MCP badge under "Enabled for" in the key list. If yours has no badge, create a new key for MCP. See Connecting AI Assistants to Manifestly.

Renaming and revoking

Edit renames a key. Delete revokes it immediately and permanently, and anything using it stops working at once, so check what that is before you click.

Treat a key like a password

  • A key acts as the account. Anyone holding it can do what it permits.
  • Do not paste one into a chat, a ticket, a spreadsheet or a screenshot.
  • Use one key per integration, so you can revoke one without breaking the others.
  • Revoke keys for tools you have stopped using. An unused live key is the one nobody notices has leaked.

Still need help? Contact Us Contact Us