Scout Trails Docs

API keys

An API key is the read credential for your organization’s data outside the dashboard. The query API and the MCP server both accept it. Keys belong to an organization, not to a person: any member can create one, and each key reads all of the organization’s telemetry.

API keys and ingest keys

Scout Trails uses two kinds of key, and they are not interchangeable.

API keyIngest key
PurposeRead data through the API or the MCP serverSend telemetry from a coding agent
Belongs toThe organizationOne actor
Looks likewb_api_ followed by 43 letters, digits, - and _A 43-character token with no prefix
Managed onManage > API keysManage > Actors & ingest keys
Shown again laterNo, only once at creationYes, on the actor’s row

An ingest key sent to the API or the MCP server is rejected as unauthenticated, and an API key sent to the ingest endpoint is rejected too. To set up an agent, see Agents.

Opening the API keys page

  1. Sign in to the dashboard at https://ui.scoutmonitoring.io.
  2. Open the organization menu (the organization name in the top bar) and select Manage.
  3. Select the API keys tab.

Every member of the organization can open this page and see every key in it.

Creating a key

Any member can create a key; no admin role is needed.

  1. On the API keys page, find the New API key card.
  2. In What is it for?, enter a name that says where the key will be used, for example Grafana dashboard or Weekly cost report. The name is required and can be up to 120 characters.
  3. Select Create key.

The page shows a confirmation banner, “API key name created.”, and a card titled with the key’s name and marked Shown once. The card contains the full key.

  1. Copy the key and store it in a secrets manager or an environment variable right away.

The key is shown exactly once. Scout Trails keeps only a one-way digest of it, so nobody, including an admin, can display it again. Reloading or leaving the page removes the card. If you lose a key, revoke it and create a new one.

If the name is only spaces, the page shows “Name the key so it can be recognised later.” and no key is created.

The key list

The All keys card lists every key in the organization, newest first. Its header shows how many keys are live out of the total, for example 2 live of 3.

ColumnShows
NameThe name entered when the key was created.
Created byThe email of the member who created the key, with a you badge on your own keys. If that member is no longer in the organization, it reads “creator has left the organization”.
CreatedThe creation date.
Statuslive, or revoked with the revocation date.

Revoked keys stay in the list so you keep a record of them. A key’s value is never shown in the list.

When the organization has no keys, the card reads “No API keys yet.” and offers Create the first key, which jumps to the New API key form, and Ingest keys are over here, which opens the Actors & ingest keys tab.

Revoking a key

Revoking a key stops it working immediately, in both the API and the MCP server. Revocation cannot be undone; create a new key if you need access again.

  1. On the API keys page, find the key in All keys.
  2. Select Revoke on its row. There is no confirmation step.

The page shows “API key revoked.” and the key’s status changes to revoked. Clients still using the key receive 401 from the API and an unknown bearer key error from the MCP server.

Who can revoke a key:

KeyAdminMember
A key you createdYesYes
A key another member createdYesNo

Every member sees a Revoke button on every live key. If a member revokes a key they are not allowed to, the page shows “Only an admin can revoke a key someone else created.” and the key stays live.

Removing a member from the organization revokes every key they created in it. See Removing a member.

Messages you can see

MessageMeaning
API key name created.The key was created. Copy it from the Shown once card.
Name the key so it can be recognised later.The name was blank.
You are not permitted to create keys in this organization.Your account is no longer a member of this organization.
API key revoked.The key no longer works.
Only an admin can revoke a key someone else created.You tried to revoke a key you did not create, and you are not an admin.
That key no longer exists.The key was removed before your request reached it.
Could not create the API key. / Could not revoke that key. / Could not load API keys.A server error. Try again.

Good practice

  • Create one key per integration, named for where it runs, so you can revoke one without breaking the others.
  • Keep keys out of source control. Read them from an environment variable or a secrets manager.
  • Revoke a key as soon as the integration that used it is retired or the key may have been exposed.

In this section