The question this page answers
Which keys can reach Tightly from outside, what can each one read and write, when was each last used, and how do I make, replace or stop one? API keys sits in the Developer group of the settings rail, beside Metrics; the Product data API row under Reads from Tightly on Integrations opens the same page.
How to call the API, which scopes each operation needs, the error codes, rate limits, versioning and the MCP door are the developer portal's: start with its Authentication, Scopes and MCP guides and its Your first request page.
What you see
One table, keys that can still reach Tightly first, then newest Created first: Label; State, Active, Expired, Stops {day}, Stopped {day} or Revoked {day}; Last used, Today, a day, or Not used yet; Key, the stored prefix and the last four characters and never more; Reads and Writes, the resources in their customer words, or Nothing; Created, the day, with who pressed it on hover or Nobody was recorded; Expires, a day or Never. Once any key is narrowed to one Tightly Connect account, an Account column stands after Last used, reading the account or Whole tenant. The footer counts every key ever minted, revoked ones included. With no key at all the table reads "No key reaches Tightly yet."
The resources are Products, Product data, Stock, Suppliers, Purchase orders, Sales, Orders, Returns, Stocktakes, Sandbox, Movements, Accounts, Order book, Sell-out, Planning, Cash, Reports and Metrics. Suppliers, Purchase orders, Orders, Returns, Stocktakes, Sandbox, Order book and Sell-out take writes; the rest are read only.
A key belongs to this tenant alone: a keyed request takes its tenant from the key and never from a header, so it cannot reach the other tenants on your company. A write scope carries its read, so a key that may post purchase orders can list them.
What to do
New key opens a drawer. Label is required. Reach is a matrix of one row per resource, each None, Read or Read and write; a resource this plan does not include shows Sold with {plan} in the cell and no control. Where the plan holds Tightly Connect and there is an account to name, Account narrows the key to one account or leaves it on Whole tenant. Expires offers In 30 days, In 90 days, In a year (the default) or Never. Allowed addresses is optional; empty reads Any address. The consequence stands before Create: "Anything holding this key can do what you ticked, as {tenant}, until it expires or you revoke it.", naming the account first where one was chosen. The receipt is the whole key, once, with Copy and the sentence "Copy it now; Tightly cannot show this key again."
Sandbox, beside New key, creates an empty second tenant on the same plan, connected to nothing, whose keys start tly_test_; the receipt gives the command that fills it.
Replace mints a new key with the same or a re-ticked reach and stops this one after a cutover you choose, Now, In 1 hour, In 24 hours (the default) or In 7 days: "A new key is created now; this one keeps working until {day}, then stops." Both keys work through the cutover. With Now it reads "A new key is created now; this one stops working the moment you press Replace." A replaced key keeps its account.
Revoke stops a key at once and keeps the record: "Anything using this key stops now; the record stays." The decline is Keep it.
Usage opens what the key did: calls and refusals over the last seven days, a chart of calls per day over thirty days, one row per operation in its customer name with its calls and refusals, the limits the key runs under, and Find a request by its request id.
Admins mint, replace, revoke and make sandboxes, because a key outlives a person; everyone else reads the table and opens Usage, and "Admins change this" stands once where the buttons would be. Replace and Revoke are offered only on a key that can still reach Tightly. The Developer group is on Tightly Essentials, Essentials+ and Pro and absent on Tightly Lite. Each resource keeps its own gate: Accounts, Order book, Sell-out and Product data are sold with Essentials+, and Planning, Cash and Reports with Pro, so a resource reads Sold with Essentials+ or Sold with Pro until the plan includes it. The plan is checked on every keyed request, so a key stops reaching a resource the day the plan drops it. The same keys open the MCP door for an agent, reads only: a key never writes through it.
When it is empty or failed
A failed read prints "The keys did not load." with Try again. A plan that does not include the public API is refused with the server's own sentence, verbatim, in place of the table:
This organisation's plan does not include the public API. It is sold with Essentials.
A key with no label reads "A label is required." under the field. A write the server refused without a sentence reads "The key was not created; nothing changed.", "The key was not replaced; nothing changed.", "The key was not revoked; nothing changed." or "The sandbox was not created; nothing changed."