API keys: how to create, use and revoke them
Generate keys so your systems can talk to the VSL Max API, with read and write access or read only.
What it is for
An API key lets one of your systems, such as a script, an ERP or an automation, access your VSL Max account through the REST API without using a person's login and password.
The Settings › API tab is only visible to admins. Only they create, see and revoke keys.
How to create a key
- Open Settings › API and click New key.
- Give it a name that says where it will be used, for example "Production" or "Sales spreadsheet".
- Choose the permission.
- Click Generate key and copy it right away.
The key is shown only once. After that, the list only shows its beginning and end. If you lose it, revoke it and create another one.
Permissions
- Read & write: the key can do through the API everything an admin does in the dashboard, whatever the role of the person who created it. Only use it in systems that really need to write.
- Read only: the key can only read data. Any attempt to create, change or delete is refused.
Two things no key can do, not even Read & write: create or revoke other API keys, and close the account. Those actions only exist in the dashboard.
The list also shows the MCP agent key, named Agente MCP. It is created from the MCP tab, not here. See What MCP is.
How to use the key
Send the key in the Authorization header of every request, after Bearer:
curl https://api.vslmax.com/videos \
-H "Authorization: Bearer mxvsl_pk_..."
API keys start with mxvsl_pk_. The Last used column shows when each key was last used, which helps you find forgotten keys.
Revoking and limits
- Revoke invalidates the key immediately. Systems still using it start getting authorization errors.
- Revoking the MCP agent key asks for your password and turns MCP off for the account: every connected assistant stops.
- An account can have up to 20 active keys. Revoke the ones you no longer use to free up room.
- Store the key like a password: in an environment variable or a secrets manager, never in published code or on a web page.
Documentation
The public API endpoint reference hasn't been published yet. If you need to integrate now, contact our support and tell us what you want to do. For the most common cases there are already no-code options: the generic webhook to receive events and Zapier for automations.