Agiler MCP uses an Agiler API key. This is separate from any subscription or API key you use with your AI provider.
Create a key
- In the dashboard, open Settings, then API Keys.
- Click Add API Key and give it a recognizable name, such as
Cursor — marketing site. - Select the scopes needed for your workflow.
- Under Project access, enable Restrict to specific workspaces or projects and select the intended resources.
- Click Create and copy the key. Agiler displays the secret only once.
Selecting a workspace includes its current and future projects. Selecting individual projects gives narrower access. Leaving the restriction off includes all projects your account can access, including future projects.
Choose scopes for the task
These combinations support project discovery as well as the task itself:
| Task | Scopes to grant |
|---|---|
| First connection and project inspection | projects:read |
| Review logs, domains, backups, or usage | projects:read |
| Edit project files | projects:read, projects.files:write |
| Run WP-CLI | projects:read, projects.wp:execute |
| Run SQL | projects:read, projects.sql:execute |
| Create or restore backups | projects:read, projects.backups:write |
| Manage domains | projects:read, projects.domains:write |
projects:read includes all project read scopes, including file, log, and usage access. For a workflow that already knows its project identifier, individual read scopes can narrow access further. projects:write grants all project sub-scopes, including SQL and WP-CLI execution; use it when the assistant needs that full level of control. See all scopes and inheritance rules.
SQL and WP-CLI execution scopes allow commands that can change data. Asking for a report does not make an execution key read-only. A SQL call’s read_only setting applies to that call, not to the key’s permissions. Backup write access also includes restoration and deletion.
Store the key in your client
Follow the setup guide for ChatGPT, Claude, Claude Code, Codex, or Cursor. The client sends:
Authorization: Bearer ak_...
Use the complete key in place of ak_.... Keep it in the client’s credential settings or local environment. Do not put it in a chat message, shared project instructions, a repository, or the endpoint URL.
Verify and change access
Ask the assistant to call whoami to identify the connected account and its effective scopes. scopes_list explains which tools each scope unlocks. Resource restrictions can still prevent access to a particular project even when the tool is available.
Use Edit API key in the dashboard to change scopes or project access. Changes apply on the next request. Refresh the client’s tool list after editing permissions, or restart the connection if the client keeps an old list.
Replace or revoke a key
To rotate a key, create a replacement, update the client, verify it with whoami, and delete the old key from API Keys. If a key has been exposed, delete it immediately and configure a new one. Deleting a key revokes it; future requests using it return 401 Unauthorized. Removing a connection from an assistant alone does not revoke the Agiler key.