https://mcp.meshpilot.app/mcp. Each key is a capability ceiling: it can never do more than the scopes you set, and never more than the live access of the person who minted it.
Mint a key
Go to Settings → MCP in the cockpit.- Give the key a name (e.g. “Cursor — Ayurpet read-only”).
- Choose access mode — read-only or read + write.
- Optionally constrain brands and platforms (leave empty for “all brands / platforms you can access”).
- Optionally set an expiry (days) and a daily rate limit (calls/day).
- Create. The full key is shown once. Copy it immediately — Mesh Pilot stores only a prefix and a hash, so it can never show you the secret again.
Key format
Keys are prefixedmp_mcp_ followed by a random secret. Only the prefix is stored in clear, so you can recognise a key in the list and in the audit log without the secret ever touching disk in plaintext.
What a key inherits
A key can only ever do what its minter can do, intersected with the scopes you set:- If you only operate two of the workspace’s brands, a key you mint can touch at most those two brands — even if you select “all.”
- If you are a viewer (read-only) on a brand, a write-mode key you mint still cannot write to that brand.
- Access is re-checked live on every request. If your access to a brand is later removed, every key you minted instantly loses that brand too — no stale grants.
Manage keys
The MCP page lists every live key with its prefix, name, scopes, access mode, expiry, rate limit, and last-used time. For each key you can:- View activity — what this key did (see Audit log).
- Revoke — kill it immediately. The revoke dialog shows the key’s recent activity first, so you can confirm what you’re cutting off.
Expiry & limits
Keys can carry an expiry date and a per-day call cap independent of your plan’s shared quota. See Limits & expiry.Connect a client with your key
Paste the endpoint + key into your AI client.