# API keys

An API key lets a command-line tool or an editor reach your Invx account over MCP. Create and revoke keys in **Settings → MCP & API**.

## Access

| Access | Can call |
|---|---|
| Read only | `list_invoices`, `get_invoice`, `get_invoice_pdf_link`, `list_clients`, `get_client`, `get_settings` |
| Read and write | Every tool, including creating, duplicating and deleting |

A read-only key that calls a write tool gets a clear refusal, and the attempt still counts against the [rate limit](/docs/mcp/limits).

Connectors you signed in with (OAuth) always have read and write access.

## Expiry

Choose 30 days, 90 days, 1 year or never. An expired key stays listed with an *Expired* badge so you can tell why a client stopped working; create a new one to replace it.

## Good to know

- **Shown once.** Invx stores only a hash. If you lose a key, revoke it and create another.
- **Up to 10 active keys.** Revoking or expiring one frees a slot.
- **Keys cannot manage keys.** Creating, listing and revoking keys needs you signed in to Invx in a browser, so a leaked key cannot mint more.
- **Signing out does not revoke keys.** Revoke a key to cut off the client that uses it, immediately.
- **Last used** is updated at most every five minutes.
- Keys start with `invx_`, so secret scanners can spot a leaked one.
