Agents and scripts authenticate with an API key from the workspace (API keys):
Authorization: Bearer mxt_…mixetape stores only a hash of each key; the key itself is shown once, when it is created. Give each agent or script its own key, so removing one never stops another.
Permissions
A key carries only the permissions ticked when it was made. An agent sees only the tools its
key allows — over MCP they are simply not listed — and a call without the permission gets a
403 naming the one it lacks.
| Permission | What it allows |
|---|---|
read |
See channels, posts, their status, playlists and captions |
publish |
Schedule, change, cancel and retry posts, and set thumbnails |
manage |
Edit videos already on the platform, manage playlists and upload captions |
comments |
Read, post, reply to and moderate comments |
analytics |
Read post and channel analytics |
storage |
Upload, import, list and delete files in mixetape’s storage |
channels |
Start connecting channels (you still approve each one on the platform) |
Tools lists which tools each permission unlocks.