API keys

Create, limit, and revoke the keys that let AI assistants and scripts work in your Dropl account.

An API key lets a tool work in your Dropl account without your password: an AI assistant connected through the Dropl MCP server, or your own script calling the Public API.

Who can create keys

Only Owners and Admins can create and revoke keys. Team members and clients can't.

A key acts as the person who created it, limited to the scopes and client sites picked for it. It stops working if that person is removed from the account or is no longer an owner or admin.

Create a key

  1. Open Settings → API keys and click Create API key.
  2. Enter a Name that says where the key is used, like "Deploy script".
  3. Pick the Scopes the tool needs. All are ticked to start; untick what it doesn't need.
  4. Under Client sites, keep All client sites or choose Only the sites I pick.
  5. Choose when it Expires: never, or in 30, 90 or 365 days.
  6. Click Create key, then copy the key.

Each account can have up to 50 active keys.

Using Cursor or Claude Code? You don't need to create a key by hand. The browser sign-in creates one for you, named after the app.

Scopes

ScopeAllows
sites:readSee your client sites
sites:writeCreate client sites
showcases:readSee showcases and their categories
showcases:writeCreate and edit showcases, categories, and tags
videos:readSee videos in your library
media:writeUpload photos and videos
embed:readGet embed codes
usage:readSee storage and delivery usage

A request that needs a scope the key doesn't have fails with INSUFFICIENT_SCOPE.

Limit a key to some client sites

A key limited to some client sites only sees and changes those sites. It can't create new client sites; that fails with SITE_RESTRICTED_KEY.

Use a site-limited key when a tool only works on one client's website.

You only see a key once

The full key is shown once, right after you create it. Copy it then: Dropl stores only a hash of it and can't show it again. Afterwards the list shows just the start of the key, like dropl_live_ab12….

Lost a key? Revoke it and create a new one.

The key list

Settings → API keys lists every key with its scopes, client sites, who created it, when it was created, last used, and expires, and whether it's active, expired, or revoked. Keys created by a browser sign-in show the app's name.

Revoke a key

  1. Open Settings → API keys.
  2. Open the key's ⋮ menu and click Revoke.
  3. Confirm with Revoke key.

Anything using the key stops working right away. Revoked keys stay in the list for 30 days so you can see what was cut off.

When keys stop working

A key is refused with INVALID_API_KEY when:

  • It was revoked.
  • It expired.
  • The person who created it was removed from the account or is no longer an owner or admin.

Keep keys safe

  • Never paste a key into an AI chat, email, or support ticket.
  • Never commit a key to a repository. Keep it in an environment variable or your host's secret settings, and make sure files like .env are in .gitignore.
  • Use one key per tool, with only the scopes and sites it needs, so you can revoke one without breaking the others.
  • If a key leaks, revoke it right away.

Next steps