---
title: "API keys and permissions"
description: "How agents authenticate, and the seven permissions a key can carry."
---

> Documentation Index
> Fetch the complete documentation index at: https://docs.mixetape.com/llms.txt
> Use this file to discover all available pages before exploring further.

# API keys and permissions

Agents and scripts authenticate with an API key from the workspace (**API keys**):

```http
Authorization: Bearer mxt_…
```

mixetape stores only a hash of each key; the key itself is shown once, when it is created.
Give each agent or script its own key, so removing one never stops another.

## Permissions

A key carries only the permissions ticked when it was made. An agent sees only the tools its
key allows — over MCP they are simply not listed — and a call without the permission gets a
`403` naming the one it lacks.

| Permission | What it allows |
|---|---|
| `read` | See channels, posts, their status, playlists and captions |
| `publish` | Schedule, change, cancel and retry posts, and set thumbnails |
| `manage` | Edit videos already on the platform, manage playlists and upload captions |
| `comments` | Read, post, reply to and moderate comments |
| `analytics` | Read post and channel analytics |
| `storage` | Upload, import, list and delete files in mixetape's storage |
| `channels` | Start connecting channels (you still approve each one on the platform) |

[Tools](/tools) lists which tools each permission unlocks.

> **A key for a pipeline**
>
> A render-and-schedule pipeline usually needs only `read`, `publish` and `storage`.

Source: https://docs.mixetape.com/concepts/api-keys/index.mdx
