MCP access
API keys are issued after access scoping.
We do not show fake keys on the public site. Workspaces receive scoped MCP tokens only after cloud access, allowed tools, and account boundaries have been reviewed.
Key policy
- Keys are scoped to specific tools and accounts.
- Read-only access is the default for cost, inventory, and readiness workflows.
- Revocation and rotation are handled during onboarding.