API keys
Create, rotate and revoke SEOFix API keys, how a key is tied to one team, how keys are stored, and how to keep them safe.
An API key (sk_...) lets an agent, script or CI job use the SEOFix REST API and MCP server for one team. Create one in Settings → Agent & MCP → Create API key, or let npx seofix connect create one for your AI agent. A key is shown once, stored only as a hash, and can be revoked at any time.
Two kinds of keys
| Kind | Created by | How many | Shown in Connected agents as |
|---|---|---|---|
| Settings key | Create API key / Rotate key in Settings → Agent & MCP | one per user | Settings key |
| CLI key | npx seofix connect, approved at /connect |
one per machine, set of agents and team | seofix connect on <hostname> · <agents> |
Both kinds work the same way on the API and MCP server. They are managed separately: rotating the Settings key does not touch CLI keys.
Create a key
In the app:
- Open Settings → Agent & MCP.
- Click Create API key. The card shows which team the key will act for.
- Copy the key from the Your new API key dialog. It is shown once; afterwards you see only its prefix (the first 12 characters).
- Click I've saved it.
For an AI agent on your computer, npx seofix connect creates a key and writes it into the agent's config for you. See Connect your agent.
Team scope
A key acts for exactly one team:
- A Settings key is bound to the team you were viewing when you created or rotated it. The card names that team.
- A CLI key is bound to the team you picked on the approval page.
Everything the key does happens in that team: it sees that team's sites, audits, fix tasks and rechecks, and nothing else. Resources of other teams answer 404 not_found. Switching teams in the app does not change what an existing key acts for. To work in another team, rotate the Settings key while viewing that team, or run npx seofix connect and pick it.
The holder must still be a member of the team. If you leave or are removed from the team, the key stops working and answers 403 team_access_revoked.
There are no finer scopes: a key can read and change everything its holder can in that team through the API, including starting audits that spend credits.
Which credits a key spends
- Audits of a plain URL (
POST /v1/crawlswithurl, MCPstart_audit) are charged to the key holder's own balance. - Audits of a registered site, scheduled audits and rechecks are charged to the team owner's balance, whoever starts them.
GET /v1/account shows both balances. See API reference.
Rotate a key
- Settings key: click Rotate key and confirm. The old Settings key stops working immediately and a new one is shown once. Update every agent and CI job that used it.
- CLI key: run
npx seofix connectagain with the same agents and the same team. It replaces that machine's previous key and updates the agent config.
Agents read their MCP config when they start, so restart them after a rotation.
Revoke a key
- Open Settings → Agent & MCP → Connected agents. Every key you hold is listed with its prefix, team, creation date and when it was last used.
- Click Revoke next to the key and confirm with Revoke key.
The key stops working immediately: requests with it answer 401 unauthenticated. You can only see and revoke your own keys.
How keys are stored
- A key is
sk_followed by 40 random characters. - SEOFix stores only a SHA-256 hash of the key and its first 12 characters (the prefix shown in Settings). The full key cannot be shown again or recovered. If you lose it, rotate or reconnect.
- The key's last use is recorded on every request.
npx seofix connectreceives the key in a single response and writes it only into the agent config files, with mode0600.
Best practice
- Treat a key like a password. It can start audits and spend credits.
- Keep keys out of repositories. Use environment variables or your CI's secret store, for example
SEOFIX_API_KEY. - In Cursor,
.cursor/mcp.jsonholds the key: keep it untracked.npx seofix connectadds it to.git/info/excludefor you. - Use separate keys for separate machines or pipelines, so you can revoke one without breaking the others.
npx seofix connectalready gives each machine its own key. - Revoke keys you no longer use. Check "last used" in Connected agents.
- If a key may have leaked, revoke it (or rotate it) at once, then reconnect your agents.
Related
More in REST API
Still stuck? Email [email protected] with your site and what you expected to see.