API keys
Create an API key with only the permissions it needs, copy it once, pause or delete it, and connect AI assistants over MCP and the zanfia command-line tool.
An API key lets a script, an automation tool or an AI assistant act on your workspace without your password. When you finish, you will have a key with a limited set of permissions, stored somewhere safe, and you will know how to pause or remove it. How to call the API with the key is covered in the developer docs: Authentication.
Open API, MCP and CLI
In the sidebar open Integrations and choose API, MCP and CLI in the Integrate Zanfia
group (/integrations/api-mcp-cli). The page has three tabs: API, MCP and CLI. On the
API tab the API keys section lists your keys, or says No API keys.
Start a new key
Click Create new API key. Name is filled in with My API key (or My API key #2 when that name is taken); change it to something that says what the key is for. A name that already exists is refused with A key with this name already exists.
Choose how long it is valid
Expires in starts at 365 days. You can pick 1 day, 7 days, 30 days, 365 days or Indefinitely. An expired key stops working and shows Expired.
Grant only the permissions it needs
Under Permissions each area has a Read and a Write checkbox, all ticked to start with. "The key can only perform the operations you enable below. Grant the least access the integration needs." At least one must stay ticked (Select at least one permission). The areas are listed in the table below.
Save and copy the key
Click Save. The API key created window warns: "This key is shown only once and cannot be retrieved later. Copy it now and store it in a safe place." The key is hidden behind dots; the eye icon reveals it and the copy button copies the full key even while it is hidden. Click Done.
Good to know
After you close the window nothing on the page can show the key again. If you lose it, delete the key and create a new one. Treat a key like a password: anyone who has it can do everything its permissions allow.
Permissions
| Area | What it covers |
|---|---|
| Products | "Products, prices, orders, clients and stats." |
| Communities | "Community channels, posts and comments." |
| Pages | "Custom hosted pages and their content." |
| Social media | "Connected social accounts, post drafts, scheduling and publishing." |
| Integrations | Email clients, Meta Conversions API and the manual payment method: connections that carry credentials. |
In the list, a key with every permission shows one Full access tag; otherwise it shows a tag per area, such as Products: Read or Communities: Read + Write.
Manage your keys
Each row shows the key's name, Valid until with a date (or Indefinitely), its permissions and its Status.
| Action | How | Result |
|---|---|---|
| See the details | Click the row | A window with Status, Created, Expires at, Permissions, Source and a copyable Key ID. The secret key itself is never shown. |
| Pause | The pause icon at the end of the row | "API key paused - requests with it are rejected until you resume it". Status turns Paused. |
| Resume | The same button, now a play icon | "API key resumed". Status returns to Active. |
| Delete | The trash icon, then confirm "Are you sure you want to delete this API key?" | "API key deleted". The key stops working for good. |
Pausing is the safe first move when you suspect a key leaked or an integration misbehaves: it takes effect at once and can be undone.
Keys you did not create by hand
Some rows are created for you and carry a badge:
| Badge | Where it comes from | What to do with it |
|---|---|---|
| CLI | Created by zanfia login on a computer. It is re-created on each login from that machine. | Nothing; you do not need to manage it by hand. |
| Connector | Created when you connected an app such as claude.ai or ChatGPT through the browser sign-in (OAuth). | Delete the row to disconnect that app. |
Connect an AI assistant or the CLI
- MCP tab. "Add Zanfia as an MCP server in claude.ai, ChatGPT, Claude Code, Codex, Cursor or VS Code and the assistant can read and manage this workspace." Connector apps sign in through the browser with no key; other clients use an API key from this page, and the key's permissions decide what the assistant may do. The tab has copyable addresses and configuration snippets for each client. Details: Connect over MCP.
- CLI tab. Two copyable commands,
npm install -g @zanfia/cliandzanfia login, install the command-line tool and sign you in through the browser, with no key needed. Details: CLI quickstart.
The API reference link under the keys table opens the developer docs.
If the page says API is disabled
If the tab shows "API integration is disabled for your account", your plan does not include API access. It is part of every current Zanfia plan; on an older plan, write to support@zanfia.com.
Was this article helpful?

