No. Create one key per project. This keeps each agent limited to the data it needs.
API keys and scopes
An API key gives an agent or script access to one Ansehn project. Its scopes decide which capabilities it can call, and it always acts with the permissions of the person who created it.
How a key works
One project. A key belongs to the project it was created in and can only read or change that project. A request cannot choose another project: a project ID in the request body is rejected, and one in a header or query string is ignored.
Its creator's permissions. Every call checks the creator's current role on the project. If the creator leaves your organization, is deactivated or loses access to the project, the key stops working. If the creator becomes a Viewer, the key can still read but can no longer change anything.
Shown once. We store only a one-way hash of the key. Nobody at Ansehn can show it to you again, so create a new key if you lose it.
One error for every failure. A missing, mistyped, revoked or expired key gets the same
401response, so the response never reveals which of these happened.
[!TIP] Create keys from an account that will keep long-term access to the project, for example a shared admin account, so the key does not stop when a team member leaves.
Choose scopes
A key can call a capability when it holds at least one of the scopes listed for that capability. Give each key only the scopes it needs.
Scope | What it unlocks |
|---|---|
Analytics Read | Every read capability: scores, citations, buying simulations, cockpit metrics, sentiment, content actions, your pages, server logs and setup |
Monitors Read | Monitors, prompts, personas, the project overview, and the AI answers and run history for each prompt |
Citations Read | Citations, citation statistics, and the most cited URLs with their details |
Competitors Read | The competitor comparison |
Server Logs Read | Server log statistics and AI crawler activity |
Content Actions Write | Updating the status of content actions. Nothing else can be changed with this key |
Server Logs Ingest | Sending server logs, for example from CloudFront or Cloudflare. It unlocks no capability |
The full list of capabilities and the scopes that grant each one is in the article "Capability reference".
Create a key
You need the Owner, Admin or Agency role on the project.
Open your project, go to Settings › Project Settings, and select API Keys.
Click Create Key.
Enter a Name that says where the key is used, for example
Claude Code, marketing team.Under Scopes, select the scopes the key needs.
Optionally set Expiration (optional) to a date. Leave it empty for a key that never expires.
Click Create Key.
Copy the key, or use Copy credentials JSON or Download credentials JSON. After you close the dialog, the key cannot be shown again.
Send the key
Send the key on every request in the Authorization header:
Authorization: Bearer ansehn_...The same header works for the HTTP API and the MCP server.
Revoke a key
Revoke a key when you no longer use it or think it was exposed.
In API Keys, find the key by its name or Key ID.
Click the delete icon in its row.
Confirm with Revoke Key.
Every request using the key fails immediately. Revoking cannot be undone.
Frequently asked questions
Can one key access several projects?
Can an API key edit personas, prompts or competitors?
No. The only change a key can make is updating the status of content actions. Other changes are made in Copilot inside Ansehn, where a person confirms each change.
Why did my key stop working?
The key was revoked or expired, or the person who created it no longer has access to the project. Create a new key from an account with access.