Keeping Your API Key Safe
A Key Is a Login, Not a Password
An API key acts with your permissions, narrowed to the boxes you ticked when you created it. Anyone holding it can do those things to your account without your password and without touching your email. Treat it like a spare set of shop keys, not like a password you can reset later.
The reassuring part is that what a key can do is bounded by design — and you choose the bounds.
Tick only what the job needs
Permissions are separate on purpose. A key that only reads analytics cannot edit a page. A key that edits links cannot manage your team. Choose the narrow set that matches the job, and make a second key later if the job grows.
Deleting is always its own permission. Removing a destination link, a landing page or a manager needs a separate destructive permission on top of the matching edit permission, and the request has to name the exact thing being removed. A key without that box ticked cannot destroy anything, whatever it is asked to do.
A manager's key is weaker than an owner's
A key can never do more than the person who created it can. Team management in particular is owner-only: a key created by a manager cannot invite, promote or revoke a manager, no matter which boxes were ticked when it was made. If a permission on a key is not effective for its owner, the API reports it as void rather than quietly pretending — which is why the "what can this key do" call is worth making first.
Handing a key to an AI assistant
- One key per tool, named for that tool, so you can switch one off without disturbing anything else.
- Use the setup prompt on the API & MCP screen. Your AI tool saves the key to a file on your computer, so it never appears in a chat message, a shared document or anything you might share publicly.
- Start narrow if you are nervous — read-only first, then widen once you trust the workflow.
- Watch the first run. Ask the assistant to describe what it is about to change before it changes it. There is a dry-run check for link changes, and a good assistant will use it.
If a key leaks
- Revoke it on the API & MCP screen in your dashboard. That is instant and permanent — the button acts the moment you click it, with no confirmation step and no waiting period.
- Create a replacement with the permissions the job actually needs.
- Check what happened. Your dashboard shows when each key was last used. Contact support with the key's name and we can look at what it did.
There is also a Rotate button next to each key. It issues a fresh key with the same permissions and leaves the old one working until you revoke it, so you can move a running integration across without downtime — but rotating alone does not close the door. Revoke the old key once the new one is in place. Apps you connected by signing in have no Rotate button. Disconnect the app and connect it again instead.
Revoking is the answer here, and it is entirely in your hands — you do not need us, and there is nothing to wait for. Nothing about revoking a key touches your subscription or your live pages; the API door is the only thing that closes.
Apps you connected by signing in
If you connected Claude, ChatGPT or another AI app through the MCP connector, there's no key for you to keep safe. To switch one off, open the API & MCP screen and click Disconnect next to it. It stops working right away.
We watch for automation that has gone wrong
Automation is expected here, and heavy but steady use is a customer using what they paid for — that is never flagged. What we do watch for is an integration that stops behaving like itself: a script stuck repeating one failing request, or a sudden change in what an account is doing. If we see something like that, a person looks first and we contact you. Nothing is switched off automatically.
The boundary that does not move
No key can grow your plan, buy anything, or create another key. Those stay with a human in the dashboard.