Create in Settings → Developer. The plaintext aivk_ appears once. GET /me returns object: api_key_session, organization_id, user_id of the minter, scopes (including implied reads) and token_last4. The secret never comes back.
The same key as MCP
| Plane | Host | Who |
|---|---|---|
| REST | api.aivyro.io /api/v1 | Scripts, Zapier/n8n, backends, SDK |
| MCP | mcp.aivyro.io /mcp | Agents (Cursor, Claude Desktop) |
You may put both families on one key or mint two. Revoking cuts every surface that used that secret. REST scopes are rest.crm.*, rest.meetings.*, rest.conversations.*, rest.sequences.* — distinct from MCP scopes.
Tenancy
The key binds one organization. Every list is that org only. GET/PATCH of an id from another org is 404, same as a random UUID. user_id on /me is the minter. The key cannot see other orgs that user also belongs to.