# API keys

Source: https://docs.tightly.io/help/settings/api-keys
Reviewed: 2026-09-07

## The question this page answers

Which keys can reach Tightly from outside, what can each one read and write, when was each last used, and how do I make, replace or stop one? API keys sits in the Developer group of the settings rail, beside Metrics; the `Product data API` row under `Reads from Tightly` on Integrations opens the same page.

How to call the API, which scopes each operation needs, the error codes, rate limits, versioning and the MCP door are the developer portal's: start with its Authentication, Scopes and MCP guides and its Your first request page.

## What you see

One table, keys that can still reach Tightly first, then newest Created first: **Label**; **State**, `Active`, `Expired`, `Stops {day}`, `Stopped {day}` or `Revoked {day}`; **Last used**, `Today`, a day, or `Not used yet`; **Key**, the stored prefix and the last four characters and never more; **Reads** and **Writes**, the resources in their customer words, or `Nothing`; **Created**, the day, with who pressed it on hover or `Nobody was recorded`; **Expires**, a day or `Never`. Once any key is narrowed to one Tightly Connect account, an **Account** column stands after Last used, reading the account or `Whole tenant`. The footer counts every key ever minted, revoked ones included. With no key at all the table reads "No key reaches Tightly yet."

The resources are `Products`, `Product data`, `Stock`, `Suppliers`, `Purchase orders`, `Sales`, `Orders`, `Returns`, `Stocktakes`, `Sandbox`, `Movements`, `Accounts`, `Order book`, `Sell-out`, `Planning`, `Cash`, `Reports` and `Metrics`. `Suppliers`, `Purchase orders`, `Orders`, `Returns`, `Stocktakes`, `Sandbox`, `Order book` and `Sell-out` take writes; the rest are read only.

A key belongs to this tenant alone: a keyed request takes its tenant from the key and never from a header, so it cannot reach the other tenants on your company. A write scope carries its read, so a key that may post purchase orders can list them.

## What to do

**New key** opens a drawer. Label is required. **Reach** is a matrix of one row per resource, each `None`, `Read` or `Read and write`; a resource this plan does not include shows `Sold with {plan}` in the cell and no control. Where the plan holds Tightly Connect and there is an account to name, **Account** narrows the key to one account or leaves it on `Whole tenant`. **Expires** offers In 30 days, In 90 days, In a year (the default) or Never. **Allowed addresses** is optional; empty reads `Any address`. The consequence stands before Create: "Anything holding this key can do what you ticked, as {tenant}, until it expires or you revoke it.", naming the account first where one was chosen. The receipt is the whole key, once, with Copy and the sentence "Copy it now; Tightly cannot show this key again."

**Sandbox**, beside New key, creates an empty second tenant on the same plan, connected to nothing, whose keys start `tly_test_`; the receipt gives the command that fills it.

**Replace** mints a new key with the same or a re-ticked reach and stops this one after a cutover you choose, Now, In 1 hour, In 24 hours (the default) or In 7 days: "A new key is created now; this one keeps working until {day}, then stops." Both keys work through the cutover. With Now it reads "A new key is created now; this one stops working the moment you press Replace." A replaced key keeps its account.

**Revoke** stops a key at once and keeps the record: "Anything using this key stops now; the record stays." The decline is Keep it.

**Usage** opens what the key did: calls and refusals over the last seven days, a chart of calls per day over thirty days, one row per operation in its customer name with its calls and refusals, the limits the key runs under, and Find a request by its request id.

Admins mint, replace, revoke and make sandboxes, because a key outlives a person; everyone else reads the table and opens Usage, and "Admins change this" stands once where the buttons would be. Replace and Revoke are offered only on a key that can still reach Tightly. The Developer group is on Tightly Essentials, Essentials+ and Pro and absent on Tightly Lite. Each resource keeps its own gate: `Accounts`, `Order book`, `Sell-out` and `Product data` are sold with Essentials+, and `Planning`, `Cash` and `Reports` with Pro, so a resource reads `Sold with Essentials+` or `Sold with Pro` until the plan includes it. The plan is checked on every keyed request, so a key stops reaching a resource the day the plan drops it. The same keys open the MCP door for an agent, reads only: a key never writes through it.

## When it is empty or failed

A failed read prints "The keys did not load." with Try again. A plan that does not include the public API is refused with the server's own sentence, verbatim, in place of the table:

> This organisation's plan does not include the public API. It is sold with Essentials.

A key with no label reads "A label is required." under the field. A write the server refused without a sentence reads "The key was not created; nothing changed.", "The key was not replaced; nothing changed.", "The key was not revoked; nothing changed." or "The sandbox was not created; nothing changed."
