API keys
An API key lets a command-line tool or an editor reach your Invx account over MCP. Create and revoke keys in Settings → MCP & API.
Access#
| Access | Can call |
|---|---|
| Read only | list_invoices, get_invoice, get_invoice_pdf_link, list_clients, get_client, get_settings |
| Read and write | Every tool, including creating, duplicating and deleting |
A read-only key that calls a write tool gets a clear refusal, and the attempt still counts against the rate limit.
Connectors you signed in with (OAuth) always have read and write access.
Expiry#
Choose 30 days, 90 days, 1 year or never. An expired key stays listed with an Expired badge so you can tell why a client stopped working; create a new one to replace it.
Good to know#
- Shown once. Invx stores only a hash. If you lose a key, revoke it and create another.
- Up to 10 active keys. Revoking or expiring one frees a slot.
- Keys cannot manage keys. Creating, listing and revoking keys needs you signed in to Invx in a browser, so a leaked key cannot mint more.
- Signing out does not revoke keys. Revoke a key to cut off the client that uses it, immediately.
- Last used is updated at most every five minutes.
- Keys start with
invx_, so secret scanners can spot a leaked one.