BlogAPI design

Each AI client gets its own key

AI connections use managed keys named after the client, so their requests can be identified separately from the rest of a team's traffic.

If an AI client uses the same key as your application, its requests end up mixed with the application's traffic. You can see the usage increase, but the key doesn't help explain where it came from.

The browser sign-in flow on /mcp gives those connections their own managed keys. When you authorize a supported client, you choose the team it will use. The connection then runs on a key named after that client, so its traffic can be identified separately in Usage.

The key belongs to the client within that team. It isn't a new key for every chat or every person who connects the same client. That keeps the grouping useful when several teammates use the same tool.

The setup also means you don't have to copy your application's secret into the client. You sign in, choose the team, and authorize the connection through the browser. The team's plan and allowances still apply to its requests. Connecting an AI tool doesn't create a separate subscription.

You can review and revoke connections on the dashboard's AI setup page. Revoking a connection removes its authorization without requiring you to rotate the application's key. Revocation can take up to ten minutes to reach an already connected client, so it isn't an instant cutoff.

That gives you a way to tell which client is making requests and to stop a connection when you no longer use it, while keeping the rest of the team's integrations running.