Isomorph

API keys for other tools

An agent key lets another AI tool (Claude Desktop, another Claude Code session, or your own software) work with one agent over the Model Context Protocol (MCP). The tool acts as you, with no more access than you have.

01

Create a key

Open the agent in the console, go to Members (in the Menu), and find API keys for other tools. Owners, admins and operators can create keys. Name the key after the tool that will use it, choose what it may do, and choose when it expires.

The key is shown once. Copy it straight into the tool; if you lose it, revoke it and create another.

02

Connect Claude Code

claude mcp add --transport http my-agent https://platform.isomorphlabs.io/api/mcp --header "Authorization: Bearer <key>"

The Members page shows this command with your key filled in right after you create it.

03

Connect Claude Desktop or another MCP client

Add a remote MCP server with the URL https://platform.isomorphlabs.io/api/mcp and the header Authorization: Bearer <key>. The server speaks Streamable HTTP (JSON-RPC 2.0 over POST).

04

What each scope allows

ScopeAllowsTools
read:tasksRead threads, what is waiting on you, schedules and files.threads_list, threads_read, approvals_list, schedules_list, files_list, files_read
write:tasksSend the agent tasks and run a schedule now.threads_send_task, schedules_fire_now
cancel:tasksCancel running tasks.(none yet)
approve:tasksApprove or deny an open request, with a note.approvals_answer

A key can never carry a scope your own role lacks. Answering approvals needs owner or admin, or being designated to approve on the Members page, and the agent still checks each decision against its approval rules.

05

Expiry and revocation

Keys expire after 90 days by default (at most 365). Revoke a key from the Members page and it stops working on its next use. An owner can revoke anyone’s key on their agent.

A key also stops working on its own if your access to the agent is removed, if your role is lowered below what the key carries, or if your account is deleted. Every use is recorded.

⚠ Note:A key can send your agent work, and your agent holds your credentials. Treat a key like a password: keep it out of shared files and chat, give it only the scopes the tool needs, and revoke it when you stop using the tool.