Admin

API Keys

An API key lets software act in your organisation without someone signing in. The Waymaker CLI, an MCP client such as Claude Desktop or Cursor, and a script in your CI pipeline all authenticate with one. **A key acts as the person who created it**: whatever a tool does with your key, it does with your access, and it is recorded against your name.

API KeysCLIMCP
Last updated: October 1, 2026•2 minutes read

Overview

An API key lets software act in your organisation without someone signing in. The Waymaker CLI, an MCP client such as Claude Desktop or Cursor, and a script in your CI pipeline all authenticate with one. A key acts as the person who created it: whatever a tool does with your key, it does with your access, and it is recorded against your name.

Keys start with wm_sk_ and are shown once, when you create them.

Where to create one

API keys are created in Admin, not in Commander.

  1. Sign in at admin.waymakerone.com
  2. Go straight to admin.waymakerone.com/api/keys. Organisation admins also see API Keys in the sidebar; members use the link
  3. Click Create API Key
  4. Name the key for what it will do — "CI deploy", "Claude Desktop", "Laptop" — not "Key 1"
  5. Tick the permissions it needs. For an MCP client this decides which tools it is offered — a read-only key sees no write tools. The key never has more access than you do. Only an organisation admin can give a key Host · Admin
  6. Set an expiry if the key is for a one-off job
  7. Copy the key and store it somewhere safe. It is not shown again. If you lose it, revoke it and create a new one.

Who creates keys

Each person creates their own keys — members included. Do not ask an admin to create a key for you: a key acts as whoever created it, so a key an admin makes would run your tool as the admin, and everything it did would be recorded as theirs.

  • Members create, see and revoke their own keys.
  • Organisation admins can also see and revoke every key in the organisation, and are the only people who can create a key with Host · Admin.
  • When someone leaves the organisation, their keys stop working — no one has to remember to revoke them.

Keeping keys safe

  • One key per purpose. A laptop, a CI job and an MCP client each get their own key, so revoking one does not break the others.
  • Never paste a key into a document, a chat, or a repository. Use your tool's settings, a .env file that is not committed, or your CI's secret store.
  • Revoke keys you no longer need — a laptop you have replaced, a CI job that is gone. You see and revoke your own keys (admins see everyone's); a revoked key stops working immediately.

Using a key

Everything about using a key is in the developer docs: