> For the complete documentation index, see [llms.txt](https://doc.wearepatchworks.com/product-documentation/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://doc.wearepatchworks.com/product-documentation/developer-hub/patchworks-core-api/core-api-authentication/api-keys.md).

# API keys

## Introduction

You can authenticate Patchworks API requests using your dashboard credentials (OAuth 2) or API keys.

If your user account has at least [manager-level permissions](/product-documentation/users-roles-and-permissions/roles-and-permissions-summary.md), you can generate and manage API keys to authenticate Patchworks API requests.

When you generate an API key, you choose an API key type (which determines what the key can be used for) and assign one or more roles (which determine what the key is permitted to see and do). This means you can issue keys with only the permissions that a given integration, tool or AI assistant actually needs - rather than every key having full manager-level access.

## Need to know

* Every API key has a **type** (`standard` or `MCP`) and one or more **roles** - see API key types & roles.
* An API key can only perform actions that are permitted by its assigned role(s). Requests that fall outside those permissions are rejected.
* Roles are assigned when a key is generated and can't be changed afterwards. To change the permissions for an existing key, generate a new key with the required roles, then revoke or delete the old one.
* API keys are associated with a company profile (not a user profile).
* You can [generate](#generating-api-keys) as many API keys as required.
* API keys do not expire, but existing keys can be [revoked](#revoking-an-existing-api-key) or [deleted](#deleting-an-existing-api-key).
* An API key must be passed as an `authorization` value in request headers.

### API key types & roles

#### API key type

The API key type determines what a key can be used for. It's displayed in the `scopes` column of your API keys list.

| Type           | Scope      | Used for                                                                                                                |
| -------------- | ---------- | ----------------------------------------------------------------------------------------------------------------------- |
| `standard key` | `Standard` | Authenticating requests to the Patchworks Core API - including requests made by a local Patchworks MCP server.          |
| `MCP key`      | `MCP`      | Connecting an AI assistant to the hosted Patchworks MCP server. For a walkthrough, see Generating a Patchworks MCP key. |

#### Roles

Roles determine what an API key is permitted to see and do. At least one role must be assigned to every key. Where multiple roles are assigned, the key has the combined permissions of all of them.

You can assign:

* **Patchworks roles** - the same roles that are available for user accounts. See our [Roles & permissions](/product-documentation/users-roles-and-permissions/roles-and-permissions-summary.md) summary for details of what each role permits.
* **Custom roles** - roles that you've defined in the [Role Manager](/product-documentation/users-roles-and-permissions/role-manager.md) (an enterprise-tier feature), with your own combination of view and edit permissions across platform areas. This is the recommended approach if you need a key that's limited to a very specific set of actions - for example, a key that can only run process flows and read run logs.

## Generating API keys

To generate a new API key, follow the steps below.

**Step 1**\
Log into the [Patchworks dashboard](https://app.wearepatchworks.com/login), then select the `general settings` option:

<div align="left"><figure><img src="https://2440044887-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FLYNcUBVQwSkOMG6KjZfz%2Fuploads%2FXSjKf2v1VCwZSqDvwpsq%2Fapi%20keys%201.png?alt=media&amp;token=ec1430c8-2275-44c9-af7e-e01528236820" alt="" width="233"><figcaption></figcaption></figure></div>

**Step 2**\
Select the `API keys` option:

<div align="left"><figure><img src="https://2440044887-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FLYNcUBVQwSkOMG6KjZfz%2Fuploads%2Fv2LIh5P8vyC8u7mlLk0K%2Fapi%20keys%202.png?alt=media&amp;token=b9ed71a1-4e81-4745-a35b-fe325e6f7399" alt=""><figcaption></figcaption></figure></div>

**Step 3**\
Click the `create API key` button and select key type:

<figure><img src="https://2440044887-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FLYNcUBVQwSkOMG6KjZfz%2Fuploads%2FQzx09Q2hUiCsJBiixkRd%2FScreenshot%202026-09-15%20at%2010.21.10.png?alt=media&amp;token=06f01517-d0da-4e59-9d88-95258f94ad7e" alt=""><figcaption></figcaption></figure>

**Step 4**

Select a role and click create:

<figure><img src="https://2440044887-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FLYNcUBVQwSkOMG6KjZfz%2Fuploads%2F42Wo6d8E3akL88ROPTat%2FScreenshot%202026-09-15%20at%2010.22.14.png?alt=media&amp;token=b0747a38-f7ce-46cd-9e82-6b8aa9bc6f01" alt=""><figcaption></figcaption></figure>

**Step 5**\
A new key is generated - you can now copy this for use in your API requests

<figure><img src="https://2440044887-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FLYNcUBVQwSkOMG6KjZfz%2Fuploads%2F91iciP5h5ur3aCFfNojZ%2FScreenshot%202026-09-15%20at%2010.28.22.png?alt=media&amp;token=277de187-c36e-40e8-bb5c-b3e0ad37db6d" alt=""><figcaption></figcaption></figure>

## **Revoking an existing API key**

Revoking an existing API key will cause requests to fail wherever this key is used, but the key remains in your list for future reference. If you're sure that you want to do this, follow the steps below.

**Step 1**\
Log into the [Patchworks dashboard](https://app.wearepatchworks.com/login), then select `general settings` | `API keys` (as shown [above](#generating-api-keys)).

**Step 2**\
Click the ellipses associated with the key to be revoked - for example:

<div align="left"><figure><img src="https://2440044887-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FLYNcUBVQwSkOMG6KjZfz%2Fuploads%2FmqIvjzpu53Cc81iyHILt%2Fapi%20key%20options.png?alt=media&amp;token=535c5be1-6690-4f9a-b1ae-856cd9154c71" alt=""><figcaption></figcaption></figure></div>

**Step 3**\
Select the `revoke` option - for example:

<div align="left"><figure><img src="https://2440044887-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FLYNcUBVQwSkOMG6KjZfz%2Fuploads%2FmCTZunRdigHfWCM7z4f4%2Frevoke%20api%20key%201.png?alt=media&amp;token=1dcd81cf-a7cf-4b79-980b-8f394e3293ad" alt=""><figcaption></figcaption></figure></div>

The key is revoked immediately and the timestamp for this action is displayed in the list of keys - for example:

<figure><img src="https://2440044887-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FLYNcUBVQwSkOMG6KjZfz%2Fuploads%2FbfXqPOSQICiWXEN7ZWSK%2Frevoke%20api%20key%202.png?alt=media&amp;token=dc811806-4651-43a1-99ec-a7ff06d63d45" alt=""><figcaption></figcaption></figure>

## Deleting an existing API key

Deleting an existing API key will cause requests to fail wherever this key is used. Deleted keys are removed entirely, so if you need to keep track of keys issued over time, you may wish to consider the [revoke](#revoking-an-existing-api-key) option instead.

If you're sure that you want to delete an API key, follow the steps below.

**Step 1**\
Log into the [Patchworks dashboard](https://app.wearepatchworks.com/login), then select `general settings` | `API keys` (as shown [above](#generating-api-keys)).

**Step 2**\
Click the ellipses associated with the key to be deleted - for example:

<div align="left"><figure><img src="https://2440044887-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FLYNcUBVQwSkOMG6KjZfz%2Fuploads%2FmqIvjzpu53Cc81iyHILt%2Fapi%20key%20options.png?alt=media&amp;token=535c5be1-6690-4f9a-b1ae-856cd9154c71" alt=""><figcaption></figcaption></figure></div>

**Step 3**\
Select the `delete` option - for example:

<div align="left"><figure><img src="https://2440044887-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FLYNcUBVQwSkOMG6KjZfz%2Fuploads%2FDa061yZWB9gaIKQ6VjiD%2Fdelete%20api%20key%201.png?alt=media&amp;token=6b74a3e4-a47e-44af-8387-769d5bff30ab" alt=""><figcaption></figcaption></figure></div>

The key is removed immediately.

## Using API keys

An API key must be passed as an `authorization` value in request headers, for all requests.

<details>

<summary><img src="https://2440044887-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FLYNcUBVQwSkOMG6KjZfz%2Fuploads%2FpLMO12yvTCxi9PorCt53%2Ficons8-film.svg?alt=media&amp;token=e59864bc-2d97-4f98-966c-a083c18e60db" alt="" data-size="line"> Show me</summary>

![](https://2440044887-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FLYNcUBVQwSkOMG6KjZfz%2Fuploads%2FfiMU2fSvA6PjN23YjQmx%2Fapi%20keys%20demo.gif?alt=media\&token=c18545d7-bb26-4443-96c6-2109349fca79)

</details>
