Mint an API key
Name it, choose its scopes, decide whether it may drive assistants or manage webhook subscriptions — and copy it once.
Navigate to: Settings → API keys & webhooks → New key (Super Administrator)
The name appears only in your own key list. Name it after the system that will hold the key — Warehouse sync, Zapier, Reporting assistant — so revoking the right one later is obvious.
Each row is a feature the API covers, with the verbs it supports. Ticking create, update or delete ticks read for you as well: a key that can write but cannot read what it wrote is a trap, not a policy.
They are grants, not data scopes — they widen where the key works, never what it may touch.
| Option | What it adds |
|---|---|
| Allow AI assistants (MCP) | The key answers at `https://api.trabalance.com/mcp`, so an assistant can use the read and proposal tools — within the scopes above. See [AI assistants](/developer/mcp). |
| Allow webhook subscriptions | The key may call `/api/v1/webhooks/*` to create and remove its own endpoints. This is what Zapier and Make use. See [Subscribe an endpoint](/developer/subscribing). |
Never, 30 days, 90 days or a year. After that the key answers 401 invalid_token — nothing is deleted, it simply stops.
The full key — tk_live_ and 64 hex characters — is shown once, with a ready-made curl. Trabalance stores only its SHA-256 fingerprint, so there is no "show it again". Lose it and you mint a new one.
Why a scope might not be offered
The dialog only offers what you can grant. When nothing is offered, the screen says which wall you have hit rather than leaving you guessing.
| Reason | What it means | What fixes it |
|---|---|---|
| Plan | The module is not on this business's subscription at all. | Add it to the plan and it appears here. |
| Role | The business has the module; this user's role does not. | A Super Administrator grants it under Settings → Roles. |
| Lapsed | The business had the module and the subscription is no longer live. | Renew. Existing keys stop working while a subscription is not live. |
Scopes are bounded to your own rights at the moment you mint — and re-checked against your rights on every request afterwards. If you are demoted, every key you minted loses the same rights that day. That is the design, not a fault.
Related
- API keys — the list, the format, revoking
- Permission scopes — what each scope reaches
- How access is decided — the three checks behind every call
- Getting started — your first call with the key