API keys and scopes

A key is a person's access, narrowed to websites and scopes. Make it as small as the job needs.

Two kinds of keys

Key Made in Covers Prefix
Workspace key Settings → API and MCP → New credential every website, or the ones you tick mr_ws_…
Website key made when the WordPress plugin or the Shopify app connects one website mr_site_…

Use a workspace key for your own scripts and assistants, and tick only the websites it needs. Both kinds are listed under Settings → API and MCP with their last use, so you can spot unused ones. Each key is shown once and limited to 1,200 requests an hour.

Scopes

Scope Allows
sites:read website summary, scores and history, speed results, the portfolio of all the key’s websites, audits
issues:read issues with evidence, AI explanations, suggested values, prioritized actions
pages:read crawled pages and findings per page
search:read Search Console summary and rows
ai:read AI visibility, answer gaps, AI crawler access, llms.txt and Agentic browsing results
issues:recheck queue a recheck, or re-run the Agentic browsing check for one page
audits:run start a full audit (reading audits needs sites:read)
actions:apply approve SEO title, description, canonical or noindex changes, llms.txt and AI crawler rules, written through the WordPress connector
content:write used by the WordPress plugin to send content; not for your own scripts

The key the WordPress plugin or the Shopify app uses carries content:write plus sites:read and pages:read, so it can also read this website’s scores back for its own screens.

Change a key

Edit on a key changes its name, its scopes and, for a workspace key, its websites. The key itself stays the same, so nothing needs a new copy. A website key stays on its website. A key the WordPress plugin or the Shopify app uses keeps its name and the scopes it needs. Keys made before a scope existed (for example ai:read or audits:run) do not have it: add it with Edit.

OAuth tokens

When an MCP client signs you in instead of taking a key (ChatGPT, for example), the token it gets is a workspace key with the read scopes you approved. It appears in the same list under Settings → API and MCP and is revoked the same way. Write scopes are never granted through OAuth.

Revoking

Settings → API and MCP → Revoke on the key. Requests with it fail with 401 from that moment. The WordPress plugin’s key can also be revoked there; the plugin then shows “disconnected” and stops sending.

Common questions

I lost a key. Can I see it again?

No. MonoRanks keeps only a fingerprint. Revoke it and make a new one.

Can I give an existing key more access?

Yes. Edit on the key changes its name, scopes and websites. The key itself stays the same, so nothing that uses it needs a new copy.

Can a client viewer make keys?

No. Keys are made by owners and members, and a key stops working if its creator becomes a client viewer or leaves the workspace.