Create and revoke MCP access keys

An MCP access key connects AI clients like Claude Code or Cursor to Project Manager. You decide what the key can do, and whether it applies to one organization or every one of your organizations.

Prerequisites
  • You're signed in to Project Manager.

Choose the right connection method

Claude.ai, Claude Desktop, and Claude Mobile connect via OAuth. You don't need a key for that. You need a key for Claude Code, Cursor, and other MCP clients.

→ Connect and set up MCP

Choose an organization

Before creating a key, switch to the organization it should apply to. Without the Account-wide option, the key is bound to whichever organization is currently active.

Create a key

  1. Open Account and, in Integrations & access, click Open.
  2. In the AI Access (MCP) section, click Generate new key.
  3. Under Key name, enter a name that identifies the client or device, for example "Claude Code – MacBook".
  4. Under Access level, choose the permissions you want.
  5. Enable Account-wide if needed.
  6. Click Generate.
  7. Click Copy key and store the key as a bearer token in your MCP client.
  8. Confirm with I've saved it.

Access levels

  • Read only: list and fetch data.
  • Read + Write: also create and change data.
  • Full access: also delete data.

Use an account-wide key

An account-wide key works for every organization you're a member of. The client sends the organization along with every request, for example via the X-Organization-Slug header. X-Organization-Id or X-Organization-Name are alternatives. You can find out which organizations are available with the list_organizations MCP tool. In the key list, an account-wide label marks such keys.

An account-wide key doesn't open up other people's organizations. Your role and the enabled modules still determine what you can use it for.

Store the key safely

The full key is only shown once, right after creation. Keep it like a password and don't share it. After that, the list only shows the name, the start of the key, last use, and access level. If a key is lost, or needs different permissions, create a new one.

Revoke a key

Click Revoke next to the relevant entry in the key list. The client can no longer sign in with that key afterward. Other keys stay unchanged.

Frequently asked questions

Can I change the organization later?

No. An organization-bound key stays tied to whichever organization was active when it was created. Create a new key for a different organization, or use an account-wide one.

Can I use the MCP key for a network drive?

No. Network drives have their own key type in the WebDAV (network drive) section. The two types are separate.

Why are some features missing despite Full access?

The key replaces neither your organization role nor the module permissions. Both still apply.

What's the last-used display for?

It shows when a key was last used. This helps you spot keys you no longer need, so you can revoke them.

Keep reading

Couldn't find your answer, or still stuck?

Go to support

Last reviewed on 2026-09-26