Every integration request is authenticated against a user, using that user's API key. Requests also need your Brand ID, which is part of the endpoint path.
Finding your Brand ID and API key
Open the admin pages (your profile menu, top-right → Admin) and go to API Keys under Integrations & Export — the User page links there too. Under API Access you'll find your Brand ID with a copy button, and below it the list of your keys.
Each key is its own identity, so give every integration a key of its own and revoke just that one when the integration is retired. To create a key, give it a Name, optionally an Expires date, and click Create key. The token is shown once, in the Copy your new API key dialog — copy it somewhere safe before you click I've saved it; if it is lost, revoke the key and create a new one. Every key is listed with its kind (Integration, or Legacy for the account key from before this page existed), its scope, when it was last used and when it expires. Revoke stops a key after a confirmation, and revoked keys stay in the list with the date they were revoked.
Your previous account-wide key keeps working — it appears as Migrated key with the Legacy badge — so nothing breaks until you choose to move an integration onto a key of its own.
AI assistants connect the same way, without you creating a key by hand: add the Resourced PLM connector at mcp.resourced.com to Claude, ChatGPT, Codex or any other MCP client, approve the connection with your PLM login, and the system mints a key for that connection alone — named after the client and valid for a year. It shows up in the list here like any other key, so revoking it is how you disconnect that assistant. The connector's own page explains the setup per client and which of its tools only read.
Ways to authenticate
There are three ways to authenticate a request:
HTTP header — send your key as the x-api-key header. This is the recommended approach for automated integrations.
Query string — add api-key as a query parameter (handy for quick manual tests).
Logged-in session — when signed in to the system in a browser, you can call an endpoint by pasting its path into the address bar. Useful for manual testing only, not for automated integrations.
The same key works in both Production and QA, since QA is refreshed from a copy of Production — so an integration built against QA keeps working when you point it at Production. The endpoint paths and Swagger reference are covered in The integration API: overview.
💡 Treat your API key like a password — don't commit it to source control or share it in tickets.

