API keys
Create, limit, and revoke the keys that let AI assistants and scripts work in your Dropl account.
An API key lets a tool work in your Dropl account without your password: an AI assistant connected through the Dropl MCP server, or your own script calling the Public API.
Who can create keys
Only Owners and Admins can create and revoke keys. Team members and clients can't.
A key acts as the person who created it, limited to the scopes and client sites picked for it. It stops working if that person is removed from the account or is no longer an owner or admin.
Create a key
- Open Settings → API keys and click Create API key.
- Enter a Name that says where the key is used, like "Deploy script".
- Pick the Scopes the tool needs. All are ticked to start; untick what it doesn't need.
- Under Client sites, keep All client sites or choose Only the sites I pick.
- Choose when it Expires: never, or in 30, 90 or 365 days.
- Click Create key, then copy the key.
Each account can have up to 50 active keys.
Using Cursor or Claude Code? You don't need to create a key by hand. The browser sign-in creates one for you, named after the app.
Scopes
| Scope | Allows |
|---|---|
sites:read | See your client sites |
sites:write | Create client sites |
showcases:read | See showcases and their categories |
showcases:write | Create and edit showcases, categories, and tags |
videos:read | See videos in your library |
media:write | Upload photos and videos |
embed:read | Get embed codes |
usage:read | See storage and delivery usage |
A request that needs a scope the key doesn't have fails with INSUFFICIENT_SCOPE.
Limit a key to some client sites
A key limited to some client sites only sees and changes those sites. It can't create new client sites; that fails with SITE_RESTRICTED_KEY.
Use a site-limited key when a tool only works on one client's website.
You only see a key once
The full key is shown once, right after you create it. Copy it then: Dropl stores only a hash of it and can't show it again. Afterwards the list shows just the start of the key, like dropl_live_ab12….
Lost a key? Revoke it and create a new one.
The key list
Settings → API keys lists every key with its scopes, client sites, who created it, when it was created, last used, and expires, and whether it's active, expired, or revoked. Keys created by a browser sign-in show the app's name.
Revoke a key
- Open Settings → API keys.
- Open the key's ⋮ menu and click Revoke.
- Confirm with Revoke key.
Anything using the key stops working right away. Revoked keys stay in the list for 30 days so you can see what was cut off.
When keys stop working
A key is refused with INVALID_API_KEY when:
- It was revoked.
- It expired.
- The person who created it was removed from the account or is no longer an owner or admin.
Keep keys safe
- Never paste a key into an AI chat, email, or support ticket.
- Never commit a key to a repository. Keep it in an environment variable or your host's secret settings, and make sure files like
.envare in.gitignore. - Use one key per tool, with only the scopes and sites it needs, so you can revoke one without breaking the others.
- If a key leaks, revoke it right away.
Next steps
- Set up with AI: connect Cursor or Claude Code.
- Public API: authentication, errors, and limits.

