API keys & scopes
Create API keys with the permissions an AI client needs, set when they expire and revoke them.
On this page
An API key lets an AI app connect to your site without signing in: Claude Code, Claude Desktop, Cursor, VS Code, Windsurf, other MCP clients and your own scripts. Each key acts as the WordPress user who created it, limited to the permissions you pick.
Apps that sign in with OAuth, such as the Claude app and ChatGPT, do not need a key. They are listed under Connected apps.

Create a key
Open the API keys tab
Go to Urmi → AI & MCP → API keys and click Create key. You can also click Create key on an app's panel in Connect a client: the name is filled in for you.
Name it
Type a Name you will recognise later, such as "Cursor on my laptop". The name appears in the activity log next to everything the key does.
Choose the permissions
Tick what the app may do: Read is always included; Content and Design are ticked by default; Site is off. Give an app only what it needs. See What each permission allows.
Choose when it expires
Pick an Expiration: 30 days, 90 days (the default), 180 days, 1 year or Never expires.
Create and copy it
Click Create key. The next window shows the key once. Click Copy and store it in your app or in a password manager.
Urmi stores only a scrambled fingerprint (a hash) of the key, not the key itself, so it cannot show it again. If you lose it, revoke it and create a new one.
Until you leave the page, the setup snippets on the Connect a client tab contain your new key. Click Set up a client in the key window to go there and copy the ready-made configuration.
What each permission allows
A key (or a connected app) gets one or more of four permissions, also called scopes. The key dialog and the approval screen describe each one in a line; the table has the details.
| Permission | Shown as | What the AI can do with it |
|---|---|---|
| Read | Read pages, templates, media, menus and settings | See your pages, posts, templates, popups, Design System, media, menus and site settings; read the build guide and widget reference; check pages for accessibility and SEO problems; search icons, fonts and openly licensed images. Always included. |
| Content | Create and edit pages, posts, media and their SEO title and description | Create, edit, duplicate and publish pages and posts; add categories and tags; upload images and set their alt text; create placeholder images and simple logos; set SEO titles and meta descriptions; find and replace text, links or colors across pages; undo AI changes. |
| Design | Change the Design System, theme templates and popups | Change the Design System (colors, fonts, text styles, buttons, layout) and go back to an earlier version; create and edit headers, footers, other theme templates and popups, and choose where they appear; attach mega menus to menu items. |
| Site | Edit menus, clear caches and read form submissions | Create menus, replace their items and assign menu locations; regenerate Urmi's CSS and clear caches; read form submissions. |
No permission lets an AI change site settings, manage plugins, themes or users, add code or delete pages. See What AI cannot do.
Permissions never go beyond what the WordPress user may do. A key created by an Editor, for example, cannot get Design or Site, because Editors cannot change the theme or manage the site.
In the key dialog, Site is only available to administrators, and Design only to users who may change the theme.
See and manage your keys
The table on the API keys tab shows, for each key:
- Name, the last four characters of the key (
urmi_key_…a1b2) and the user it belongs to - Permissions
- Created and Last used (point at a date to see the exact time)
- Expires: the date, or Never
The number next to the tab name counts active keys. Expired and revoked keys are hidden; turn on Show revoked to list them too. They are marked Expired or Revoked.
Revoke a key
Revoke a key when you stop using an app, when a laptop is lost, or when you think a key has leaked.
- On the API keys tab, click Revoke next to the key.
- Confirm with Revoke key.
Every app using that key loses access immediately. This cannot be undone: to connect the app again, create a new key.
Good practice
- Create one key per app and computer, so you can revoke one without breaking the others.
- Prefer an expiration date. Create a new key when it runs out.
- Keep keys out of shared files and Git repositories. Put them in your user settings, not in a project.
- Check the Activity tab now and then to see what each key did.