Docs

API keys & scopes

Create API keys with the permissions an AI client needs, set when they expire and revoke them.

On this page

An API key lets an AI app connect to your site without signing in: Claude Code, Claude Desktop, Cursor, VS Code, Windsurf, other MCP clients and your own scripts. Each key acts as the WordPress user who created it, limited to the permissions you pick.

Apps that sign in with OAuth, such as the Claude app and ChatGPT, do not need a key. They are listed under Connected apps.

The API keys tab with two keys, Claude Desktop and Cursor, their permissions, when they were created and last used, when they expire, and a Revoke button
Urmi → AI & MCP → API keys

Create a key

  1. Open the API keys tab

    Go to Urmi → AI & MCP → API keys and click Create key. You can also click Create key on an app's panel in Connect a client: the name is filled in for you.

  2. Name it

    Type a Name you will recognise later, such as "Cursor on my laptop". The name appears in the activity log next to everything the key does.

  3. Choose the permissions

    Tick what the app may do: Read is always included; Content and Design are ticked by default; Site is off. Give an app only what it needs. See What each permission allows.

  4. Choose when it expires

    Pick an Expiration: 30 days, 90 days (the default), 180 days, 1 year or Never expires.

  5. Create and copy it

    Click Create key. The next window shows the key once. Click Copy and store it in your app or in a password manager.

The key is shown only once

Urmi stores only a scrambled fingerprint (a hash) of the key, not the key itself, so it cannot show it again. If you lose it, revoke it and create a new one.

Until you leave the page, the setup snippets on the Connect a client tab contain your new key. Click Set up a client in the key window to go there and copy the ready-made configuration.

What each permission allows

A key (or a connected app) gets one or more of four permissions, also called scopes. The key dialog and the approval screen describe each one in a line; the table has the details.

PermissionShown asWhat the AI can do with it
ReadRead pages, templates, media, menus and settingsSee your pages, posts, templates, popups, Design System, media, menus and site settings; read the build guide and widget reference; check pages for accessibility and SEO problems; search icons, fonts and openly licensed images. Always included.
ContentCreate and edit pages, posts, media and their SEO title and descriptionCreate, edit, duplicate and publish pages and posts; add categories and tags; upload images and set their alt text; create placeholder images and simple logos; set SEO titles and meta descriptions; find and replace text, links or colors across pages; undo AI changes.
DesignChange the Design System, theme templates and popupsChange the Design System (colors, fonts, text styles, buttons, layout) and go back to an earlier version; create and edit headers, footers, other theme templates and popups, and choose where they appear; attach mega menus to menu items.
SiteEdit menus, clear caches and read form submissionsCreate menus, replace their items and assign menu locations; regenerate Urmi's CSS and clear caches; read form submissions.

No permission lets an AI change site settings, manage plugins, themes or users, add code or delete pages. See What AI cannot do.

Permissions never go beyond what the WordPress user may do. A key created by an Editor, for example, cannot get Design or Site, because Editors cannot change the theme or manage the site.

Note

In the key dialog, Site is only available to administrators, and Design only to users who may change the theme.

See and manage your keys

The table on the API keys tab shows, for each key:

  • Name, the last four characters of the key (urmi_key_…a1b2) and the user it belongs to
  • Permissions
  • Created and Last used (point at a date to see the exact time)
  • Expires: the date, or Never

The number next to the tab name counts active keys. Expired and revoked keys are hidden; turn on Show revoked to list them too. They are marked Expired or Revoked.

Revoke a key

Revoke a key when you stop using an app, when a laptop is lost, or when you think a key has leaked.

  1. On the API keys tab, click Revoke next to the key.
  2. Confirm with Revoke key.

Every app using that key loses access immediately. This cannot be undone: to connect the app again, create a new key.

Good practice

  • Create one key per app and computer, so you can revoke one without breaking the others.
  • Prefer an expiration date. Create a new key when it runs out.
  • Keep keys out of shared files and Git repositories. Put them in your user settings, not in a project.
  • Check the Activity tab now and then to see what each key did.