API Keys
Create and manage API keys to access the Currents REST API, MCP server, and integrations
API keys authenticate programmatic access to Currents - the REST API, the MCP Server, the CLI tools, and other integrations. Every request is authorized against the permissions of the API key it carries, not the dashboard role of the user who created it.
API keys are organization-wide credentials. They should be treated like passwords - stored in a secret manager and never committed to source control.
Managing API Keys
Only organization Admins can create or revoke API keys. Actions Admin and Member roles can view existing keys, while Guest users cannot. See Manage Team for the full permissions matrix.
To create a key:
Navigate to Organization → API Keys
Click Create API Key
Set a label (used to identify the key in audit logs and notifications)
Choose the key permission (see below)
Copy the generated key - it is shown only once
API Key Permissions
Each key is assigned one of two permission levels that govern what it can do across the entire organization:
Read Only
Read-only access to GET endpoints (runs, tests, analytics, metrics).
Read & Write
Full read access plus write operations (create, update, delete).
Authorization is enforced server-side at the REST API layer. A Read Only key that attempts a write operation - deleting a run, creating a webhook, changing an action, or creating a Jira issue - is rejected with an HTTP 403 Forbidden, regardless of which client or tool issued the request.
Legacy keys created before permission levels were introduced default to Read & Write for backward compatibility. For read-only access, a new key with the Read Only permission should be created rather than reusing an older key.
Scope
API key permissions are organization-wide. A key applies to all projects and data in the organization exposed by the endpoints it can reach. There is currently no per-project, per-tool, or per-endpoint key scoping - only the Read Only vs Read & Write distinction.
Using API Keys
The key is passed as a bearer token in the Authorization header:
For MCP and integration setups, the key is provided through the relevant configuration (for example the CURRENTS_API_KEY environment variable). See the MCP Server documentation for details.
Last updated
Was this helpful?