Create and manage API keys
Generate an API key with the access it needs and an expiry, use it with the REST API or MCP, and revoke it when you're done.
Last updated
An API key lets a script, Zapier, or an AI tool act in your workspace through the Victoria AI REST API or MCP server. Only owners and admins can create, see and revoke keys.
Generate an API key
- Go to Settings → API Keys and select Generate Key.
- Enter a Key name you'll recognize later, such as "Zapier".
- Under Access, set each area to None, Read or Write: Leads, Campaigns, CRM and Sender accounts. Write includes read. Pick at least one area.
- Choose when it Expires: Never, 30 days, 90 days or 1 year.
- Select Generate.
- Copy the key from the yellow box that warns it won't be shown again, then select I've saved this key.
The key starts with vk_. Store it somewhere safe; Victoria AI can't show it again. Scopes and expiry can't be changed later, so generate a new key if you need different access.
Choose API key access
Give each key the least access it needs. A key that only reads campaign results needs Campaigns: Read and nothing else. A key that adds leads to a campaign needs Leads: Write. The full list of what each scope allows is in the API docs under Authentication.
Use an API key
Send the key as a bearer token: Authorization: Bearer vk_…. The same key works for the REST API and for MCP hosts that take a header. See Authentication and Connect your AI.
Each key's row shows when it was created, when it was last used, its expiry and its scopes.
Revoke an API key
- In Settings → API Keys, select the trash icon on the key's row.
- Confirm with Revoke key.
Anything using the key (scripts, Zapier, an AI connector set up with it) stops working immediately. This can't be undone.
API key stopped working
- The row says Expired: the key passed its expiry date. Generate a new key and update the integration.
- The key was revoked: generate a new one.
- A request is refused for missing scope: the key doesn't have access to that area. Generate a key with the access the request needs.
- You can't see API Keys or Generate Key fails: only owners and admins can manage keys. Ask one to create the key.