Skip to main content
Give each integration the access it needs. Keep tenant secret keys on trusted servers, use scoped Agent Connections for unattended agents, and connect interactive MCP clients through OAuth. The keys and workspace roles on this page are Locus Pro Enterprise features. For self-serve setup, see Connect your agent.

Choose a credential

An Agent Connection keeps an agent tied to its assigned account and limits. Use it when the credential will live inside an agent runtime. Use a sandbox key for integration tests.

Issue and revoke safely

1

Verify your identity

Sign in as a workspace owner or admin and complete MFA or passkey verification.
2

Create a scoped key

Open API Keys and choose the scopes your integration needs.
3

Store and test

Save the raw value in your server’s secret manager. Locus shows it only once. Check access and test the integration before retiring the old credential.
You can rotate a key with a grace period so the old and new values overlap during deployment. Revoke credentials that are no longer in use and review the credential audit in the dashboard.
Never put a tenant secret key in browser code, a mobile app, a prompt, or a source repository. For customer-facing browser features, issue a short-lived end-user token on your server.

Enterprise management scopes

Scopes do not override workspace roles. Sensitive changes, including API-key lifecycle, membership, spend controls, and payout settings, require a workspace owner or admin with recent MFA or passkey verification. An API key cannot satisfy that requirement. Custom API changes remain owner-only.

Automating Agent Connections

A server key with both credentials:manage and credits:move can create or rotate Agent Connections without human verification. Revocation needs only credentials:manage. Dashboard callers need an owner or admin role and recent verification.

Enterprise workspace roles and invitations

Custom API changes are restricted to the owner. The original owner cannot be removed or reassigned. An owner or admin can invite members from Team. Assign one non-owner role to each invitee. Invitations expire after seven days; an owner or admin can resend or revoke them. Membership changes require recent MFA or passkey verification.

Check access

Use the credential endpoint to see the current credential’s scopes and role:
The response contains authorization metadata, never the raw secret. Dashboard sessions with multiple workspace memberships must also identify the active workspace with X-Locus-Tenant-Id.

Handle authorization errors

Repeating the same request does not resolve missing access. The API reference lists each route’s requirements. See Account setup for sign-in methods.