Skip to content

API keys and permissions

How agents authenticate, and the seven permissions a key can carry.

Updated View as Markdown

Agents and scripts authenticate with an API key from the workspace (API keys):

Authorization: Bearer mxt_…

mixetape stores only a hash of each key; the key itself is shown once, when it is created. Give each agent or script its own key, so removing one never stops another.

Permissions

A key carries only the permissions ticked when it was made. An agent sees only the tools its key allows — over MCP they are simply not listed — and a call without the permission gets a 403 naming the one it lacks.

Permission What it allows
read See channels, posts, their status, playlists and captions
publish Schedule, change, cancel and retry posts, and set thumbnails
manage Edit videos already on the platform, manage playlists and upload captions
comments Read, post, reply to and moderate comments
analytics Read post and channel analytics
storage Upload, import, list and delete files in mixetape’s storage
channels Start connecting channels (you still approve each one on the platform)

Tools lists which tools each permission unlocks.

Navigation

Type to search…

↑↓ navigate↵ selectEsc close