Skip to main content
API keys authenticate programmatic requests to Noetive. The MCP server uses an API key to connect your editor to Semantik on your behalf. One key reaches both Semantik and Bud. Keys begin with keya_. Every key belongs to an agent. The agent decides which namespaces the key can reach, so two keys on the same account can have different access. Rotating a key does not change what its agent reaches, and narrowing an agent applies to every key it holds.

Agents

This is how a key is scoped in Semantik. An agent is whatever holds a key: a bot, a service, an editor. Manage them at Agents. An agent reaches either:
  • all your namespaces, including ones you create later, or
  • only the namespaces you pick.
The shared global namespace is a separate choice, so an agent can work entirely inside your own namespaces without touching it.
Give each thing that holds a key its own agent. A leaked key then costs you that agent’s namespaces rather than the whole account, and you can stop it without disturbing anything else.
Disabling an agent stops every key it holds. Deleting one requires revoking its keys first, so you see what you are about to break. If a namespace an agent was scoped to is deleted, the agent quietly reaches less than it did. The Agents page says so rather than leaving you to find out from a failing request.

In Bud

The same key reaches its agent’s own mailbox, calendar, and address book in Bud. The agent’s mailbox is set up on the key’s first request to Bud. A key must belong to an agent to reach Bud. Bud scopes are fixed (mail, cal, book, blob, approve, freebusy), with no picker. Reaching another agent’s objects needs a grant, and access never crosses your account.

Creating a key

The full key value is shown only once, immediately after creation. Copy it before navigating away: you cannot retrieve it again.
  1. Go to Settings → Developer keys.
  2. Choose the agent the key belongs to. If you have none yet, create one at Agents first.
  3. Select Create key.
  4. Choose an expiration: Never, 30 days, 90 days, or 1 year.
  5. Copy the key immediately.
After creation, the key appears in the list with only the first and last characters visible.

Constraints

Revoking a key

Revoking a key is irreversible. If the MCP server is using the revoked key, reconnect it with a new key.
Select Revoke next to any key in Settings → Developer keys. New requests to both Semantik and Bud are refused within about a minute. In Semantik, subscriptions that were already open are also disconnected rather than left streaming. To stop everything an agent can do at once, disable the agent instead. That takes effect on the same timescale and does not destroy the keys, so you can turn it back on. To rotate without downtime: issue a second key for the same agent, move your service onto it, then revoke the first. Store keys in environment variables or a secrets manager. Do not commit them to source control.