Two lists, in that order
Identities first, keys second — because a key can never do more than the identity it acts as, so reading a key’s scopes without having read the identity behind it is reading half the answer.An identity is not only for a traditional integration. The same mechanism is what a connected AI
assistant runs on: the MCP server carries an identity and a key exactly like any
other machine caller, and appears in both lists here like one.
Creating an identity
New identity asks for a code (its permanent address — lower case letters, digits and hyphens), a name, and what it’s for. It starts with no roles, acting only as itself, and reaching every site. Nothing here grants it anything. Give it the roles the integration needs on Access, narrow it to a site there if it should only reach one, and come back here to issue it a key.Acting as itself, or as a person
Acts as toggles between two things a key on this identity can do:
This is off by default on purpose: an ordinary integration key must not be able to become anybody.
Turning it on is a sentence an administrator reads, not a property a key picks up by being used a
certain way — and it is what an integration serving several different people needs, the MCP server
being the case this product ships with.
Issuing a key
Issue a key asks which identity it acts as, a name, how long it lasts, and what to narrow it to.Rotating and revoking
Rotate issues a successor with the same name, identity and scopes, and gives the key it replaces a grace window — up to 90 days — so whatever uses it can be moved over before it stops. The window only ever brings the old key’s expiry in, never past the date it already had. Revoke stops a key being traded for a token at once, and needs a reason — somebody will ask, months later, when an integration stops working and nobody remembers whether it was deliberate. There is no undo; a replacement is a new key. Suspend, on an identity, stops every key it holds at once — including ones nobody remembers issuing. It’s the bigger action, which is why it sits on the identity rather than on a key.Using a key
A key is never sent on an ordinary request. It’s traded once for a session token, and the token — good for fifteen minutes — goes on every request after that, the same way a browser’s session does: the same roles, the same site limits, the same audit trail.Who can manage this
Unlike workflows and rules, none of this is on the
Maintenance Administrator’s default pattern — a credential that can reach the whole API is not
maintenance configuration. See roles.
MCP
How an AI assistant connects to this data using exactly this kind of credential.

