API keys and connected apps
When to use OAuth and when a personal API key, how to create one, and how to revoke access.
There are two ways to authenticate the connector, and they suit different situations.
OAuth or API key
| OAuth | Personal API key | |
|---|---|---|
| Best for | claude.ai, ChatGPT, Copilot Studio: apps with a browser sign-in | terminals, scripts, self-hosted clients |
| Setup | click through a sign-in and authorization page | paste a key into a config file |
| Organization | chosen during authorization | bound to the key when you create it |
| Revoking | disconnect the app | revoke the key |
If your client supports OAuth, prefer it: there is no secret to leak.
Creating an API key
Open API keys in the app, click Create API key, name it after the tool that will use it ("My Claude Code", "Bid team script") and pick the organization it may access.
The key is shown once. Copy it immediately; for security we cannot show it again. A lost key is not a problem, revoke it and create a new one, which takes seconds.
Send it as a bearer token:
Authorization: Bearer pt_your_keyRules of thumb
- One key per tool. Then revoking one does not break the others.
- Never commit a key to a repository or paste it into a chat.
- Keys are personal. Do not share one across a team; each member creates their own.
Connected apps and revoking
Connected apps lists every app you authorized through OAuth, with the organization it may access and since when. Disconnect revokes it immediately.
For API keys, use Revoke key on the API keys page. Both take effect at once, and so does losing membership in an organization: access is re-checked on every single call.