API keys
Every external request to Shanone — whether over the MCP server or the REST API — authenticates with an API key in the form:X-API-Key: sh_xxxxxxxxxxxxxxxx is also accepted as an alternative header.
Creating a key
1
Sign in
Go to app.shanone.ai and sign in.
2
Open API Keys
Go to Settings → API Keys.
3
Create a key
Click Create API Key, give it a descriptive name, and choose an expiration. The default is 30 days.
4
Copy the key
Click Create and copy the plaintext key. Save it securely before closing the dialog; it cannot be displayed again.
Expiration
Choose how long a key can be used when you create it:
The lifetime starts when Shanone creates the key, using the server’s clock. One day means 24 hours. Using a key does not extend its lifetime. The creation confirmation and API Keys list show the expiration date and time, including the time zone.
Existing keys created without an expiration remain non-expiring. The 30-day default applies to new keys; it does not add an expiration to existing keys. Choose Never explicitly when creating a new non-expiring key.
When a key expires
At the expiration time, the key stops authenticating new requests to the REST API and MCP server. Expired keys remain in the API Keys list with an Expired status.
You cannot extend a key’s lifetime after creation or reactivate an expired or revoked key. Create a new key and update every client, environment variable, or secret that used the old one. Follow Rotating keys before expiration to avoid interruptions.
Expiration and revocation apply to new authentication checks. They do not cancel work or streams that have already been authenticated.
Scoping a key
Every key can optionally be restricted beyond the defaults:
Available
permissions values:
A key with no
permissions specified has full access. Scope keys down for anything you’re embedding in a script or service you don’t fully trust.
The direct MCP endpoint needs one more thing
If you connect straight tohttps://app.shanone.ai/mcp (Streamable HTTP) instead of going through Shanone’s local stdio proxy, you also need your organization ID as a second factor, sent as X-Org-Id (or ?org_id= in the URL as a fallback for clients that can’t set custom headers):
/api/v1/tools/... etc.) and the local stdio proxy do not require this second factor; they authenticate with the API key alone.
Example requests
- cURL
- Python
- JavaScript
Rate limits
Raise a key’s limits from Settings → API Keys if you’re consistently hitting them.
Key management
Rotating keys
1
Create a new key
From Settings → API Keys, create a replacement before the current key expires and choose its expiration.
2
Update your clients/scripts
Swap the new key in wherever the old one was configured.
3
Revoke the old key
Once you’ve confirmed the new one works.
Revoking vs. deleting
To revoke an active key, open its … menu in Settings → API Keys, select Revoke, and confirm. New authentication attempts are rejected as soon as revocation completes. The key remains in the list with a Revoked status so you can keep its record. Delete removes the key’s record and also prevents further authentication. Neither operation can be undone. Replace a key in your clients before revoking or deleting it if they still need access. Revoke a key immediately if you suspect it has been exposed.Security best practices
Use environment variables
Never hardcode a key in a committed config file or source file.
Scope to what's needed
Restrict
permissions and allowed_ips, and choose a lifetime that matches how long the key is needed.One key per machine/agent
So you can revoke individually without breaking everything else.
Rotate periodically
Replace keys before they expire. Revoke exposed or unused keys, including non-expiring ones.