Theme
AI tools
Keys
Most tools authenticate with a key. Claude Desktop is the exception: it signs in with your Vythos account instead, and needs no key at all.
Create one
AI tools → New key. Give it a label naming the tool it's for — Cursor, Claude Code, agency bot — and copy it.
The key is shown once. Vythos keeps only a hash of it and the first few characters, so the page can show you vyk_live_abc… in the list. Nobody at Vythos can read your key back to you; if you lose it, revoke it and make another.
What a key carries
The access of the person who created it. Not the workspace's access — theirs. A freelancer's key reaches exactly what the freelancer reaches: the categories they're allowed, and the clients they're assigned.
That has a useful consequence: to change what a tool can see, change that person's access on the Members page. Nothing to re-issue.
A key does not let a tool:
- see another person's memory;
- add, change or retire a rule;
- act outside the workspace it was made in.
Use one
Send it as a header:
Authorization: Bearer vyk_live_…Per-tool configuration is on Connect a tool.
Look after it
- One key per tool. Then revoking one doesn't disturb the others, and "last used" tells you which tool is actually working.
- Treat it like a password. Don't paste it into a shared document, a ticket or a chat.
- Keep it out of your repository. A key in
.cursor/mcp.jsonthat gets committed is a key you should revoke. Use your tool's secret handling, or keep the file out of version control. - Revoke on a change of hands. When a freelancer finishes, revoke their keys as well as their access.
Revoke one
AI tools, find the key, revoke it. It stops working immediately; any tool using it gets an authentication error on its next call.
What you can see
For each key: its label, its first characters, when it was created, and when it was last used. For Claude Desktop connections: the same, without a key.
"Last used" is the quickest way to spot a tool you've forgotten about. If a key hasn't been used in months, revoke it.
