API keys for other tools
An agent key lets another AI tool (Claude Desktop, another Claude Code session, or your own software) work with one agent over the Model Context Protocol (MCP). The tool acts as you, with no more access than you have.
Create a key
Open the agent in the console, go to Members (in the Menu), and find API keys for other tools. Owners, admins and operators can create keys. Name the key after the tool that will use it, choose what it may do, and choose when it expires.
The key is shown once. Copy it straight into the tool; if you lose it, revoke it and create another.
Connect Claude Code
claude mcp add --transport http my-agent https://platform.isomorphlabs.io/api/mcp --header "Authorization: Bearer <key>"
The Members page shows this command with your key filled in right after you create it.
Connect Claude Desktop or another MCP client
Add a remote MCP server with the URL https://platform.isomorphlabs.io/api/mcp and the header Authorization: Bearer <key>. The server speaks Streamable HTTP (JSON-RPC 2.0 over POST).
What each scope allows
| Scope | Allows | Tools |
|---|---|---|
| read:tasks | Read threads, what is waiting on you, schedules and files. | threads_list, threads_read, approvals_list, schedules_list, files_list, files_read |
| write:tasks | Send the agent tasks and run a schedule now. | threads_send_task, schedules_fire_now |
| cancel:tasks | Cancel running tasks. | (none yet) |
| approve:tasks | Approve or deny an open request, with a note. | approvals_answer |
A key can never carry a scope your own role lacks. Answering approvals needs owner or admin, or being designated to approve on the Members page, and the agent still checks each decision against its approval rules.
Expiry and revocation
Keys expire after 90 days by default (at most 365). Revoke a key from the Members page and it stops working on its next use. An owner can revoke anyone’s key on their agent.
A key also stops working on its own if your access to the agent is removed, if your role is lowered below what the key carries, or if your account is deleted. Every use is recorded.