API keys and scopes
A key is a person's access, narrowed to websites and scopes. Make it as small as the job needs.
Two kinds of keys
| Key | Made in | Covers | Prefix |
|---|---|---|---|
| Workspace key | Settings → API and MCP → New credential | every website, or the ones you tick | mr_ws_… |
| Website key | made when the WordPress plugin or the Shopify app connects | one website | mr_site_… |
Use a workspace key for your own scripts and assistants, and tick only the websites it needs. Both kinds are listed under Settings → API and MCP with their last use, so you can spot unused ones. Each key is shown once and limited to 1,200 requests an hour.
Scopes
| Scope | Allows |
|---|---|
sites:read |
website summary, scores and history, speed results, the portfolio of all the key’s websites, audits |
issues:read |
issues with evidence, AI explanations, suggested values, prioritized actions |
pages:read |
crawled pages and findings per page |
search:read |
Search Console summary and rows |
ai:read |
AI visibility, answer gaps, AI crawler access, llms.txt and Agentic browsing results |
issues:recheck |
queue a recheck, or re-run the Agentic browsing check for one page |
audits:run |
start a full audit (reading audits needs sites:read) |
actions:apply |
approve SEO title, description, canonical or noindex changes, llms.txt and AI crawler rules, written through the WordPress connector |
content:write |
used by the WordPress plugin to send content; not for your own scripts |
The key the WordPress plugin or the Shopify app uses carries content:write plus sites:read and pages:read, so it can also read this website’s scores back for its own screens.
Change a key
Edit on a key changes its name, its scopes and, for a workspace key, its websites. The key itself stays the same, so nothing needs a new copy. A website key stays on its website. A key the WordPress plugin or the Shopify app uses keeps its name and the scopes it needs. Keys made before a scope existed (for example ai:read or audits:run) do not have it: add it with Edit.
OAuth tokens
When an MCP client signs you in instead of taking a key (ChatGPT, for example), the token it gets is a workspace key with the read scopes you approved. It appears in the same list under Settings → API and MCP and is revoked the same way. Write scopes are never granted through OAuth.
Revoking
Settings → API and MCP → Revoke on the key. Requests with it fail with 401 from that moment. The WordPress plugin’s key can also be revoked there; the plugin then shows “disconnected” and stops sending.
Common questions
I lost a key. Can I see it again?
No. MonoRanks keeps only a fingerprint. Revoke it and make a new one.
Can I give an existing key more access?
Yes. Edit on the key changes its name, scopes and websites. The key itself stays the same, so nothing that uses it needs a new copy.
Can a client viewer make keys?
No. Keys are made by owners and members, and a key stops working if its creator becomes a client viewer or leaves the workspace.