> ## Documentation Index
> Fetch the complete documentation index at: https://help.onlyx.ai/llms.txt
> Use this file to discover all available pages before exploring further.

> ## Agent Instructions
> You are reading OnlyX Help: the OnlyX Help Center and the OnlyX developer documentation. OnlyX is an AI chatting and CRM platform for OnlyFans agencies. Its AI chatter is called Hugo in the app.
> Pages at the site root (for example /inbox/..., /hugo/..., /billing/...) are Help Center articles for agency owners, admins, chatters and creators who use the app at app.onlyx.ai. Words in bold are the exact button, menu and label names the app shows; keep them exactly as written. When these pages do not answer a question, the person can email support at support@onlyx.ai.
> Pages under /developers are the developer documentation. REST API base URL: https://api.onlyx.ai/v1 (authenticate with `Authorization: Bearer <API key>`; keys start with onx_sk_ and are created in app.onlyx.ai under Settings > API & MCP). MCP server: https://mcp.onlyx.ai/mcp (OAuth, or a Bearer API key). In the API the AI chatter is `ai` on the wire. Money is integer US cents in fields ending in Cents; timestamps are UTC ISO-8601.
> Rules for assistants acting on a user's behalf: discover ids with list calls and never invent them; before any call that reaches a real fan or the live OnlyFans account (sending a message, releasing a chat to the AI, turning AI on for a chat, resolving a hand-off, turning review mode off, changing the welcome message, creating a tracking link) show the user the exact content and get explicit confirmation; send every POST with an Idempotency-Key and reuse it on retry; never resend a message whose delivery status is unconfirmed; never ask a creator for her OnlyFans password or codes - she signs in herself through a connect link and the OnlyX Login app.

# Create and manage API keys

> Create an API key for your own tools, choose what it may do and which creators it sees, then rename or revoke it. Keys belong to the workspace.

<Badge color="orange">Owners and admins</Badge>

An <Tooltip tip="A secret code that lets another app or script use your OnlyX workspace.">API key</Tooltip> lets your own scripts and tools, such as a Zapier automation, use your OnlyX workspace. You choose what each key may do.

## Before you start

* You need an owner or admin account.
* For Claude, ChatGPT, Cursor, VS Code or Claude Code, you do not need a key. Connect them as shown in [Use OnlyX from Claude, ChatGPT, Cursor or VS Code](/referrals-and-developers/connect-an-ai-assistant).
* Keys belong to the workspace, not to the person who creates them. Every owner and admin can see and revoke every key.
* A workspace can have 25 active keys. Revoked keys and expired keys do not count.
* Give each tool its own key, with only the access it needs.

## Create a key

<Steps>
  <Step title="Open the API keys card">
    In OnlyX, click **Settings**. Then click **API & MCP**. On a phone, tap **More**, then **Settings**, then **API & MCP**.

    The **API keys** card lists the keys of this workspace.
  </Step>

  <Step title="Open the create window">
    On the **API keys** card, click **Create API key**. The **Create API key** window opens.
  </Step>

  <Step title="Name the key">
    In **Name**, enter what will use the key, for example "Zapier" or "Weekly report script". You see this name in the list later.
  </Step>

  <Step title="Choose what the key may do">
    Under **Access**, keep **Read only** unless the tool must change something. **Read only** reads the inbox, fans, stats and settings, and changes nothing.

    **Full access** allows everything, including messaging fans. **Custom** lets you tick each permission yourself. It starts from the choice you had before.

    <Warning>
      Some permissions reach real fans. If you pick one, the window says "This key can reach real fans. It can:". Then it lists what the key can do.
    </Warning>

    <Frame caption="**1** How much the key may do · **2** The warning for permissions that reach fans · **3** Create key">
      <img className="block dark:hidden" src="https://mintcdn.com/onlyx/k92DfOYEl42ZUgyg/images/help/referrals-and-developers/api-keys/create-dialog-light.png?fit=max&auto=format&n=k92DfOYEl42ZUgyg&q=85&s=6ece7f0c36dab41514306bfaf14f9d58" alt="The Create API key window with Full access selected, the warning that this key can reach real fans, and the Create key button" width="1440" height="1600" data-path="images/help/referrals-and-developers/api-keys/create-dialog-light.png" />

      <img className="hidden dark:block" src="https://mintcdn.com/onlyx/k92DfOYEl42ZUgyg/images/help/referrals-and-developers/api-keys/create-dialog-dark.png?fit=max&auto=format&n=k92DfOYEl42ZUgyg&q=85&s=17718b4f650950c268fcb16ec00d4cd4" alt="The Create API key window with Full access selected, the warning that this key can reach real fans, and the Create key button" width="1440" height="1600" data-path="images/help/referrals-and-developers/api-keys/create-dialog-dark.png" />
    </Frame>
  </Step>

  <Step title="Choose the creators">
    Under **Creators**, keep **All creators**: every creator in the workspace, including ones you add later.

    Or click **Only some creators**, then click each creator the key may see. The key sees nothing about the others.
  </Step>

  <Step title="Choose when the key expires">
    Under **Expires**, click **Never**, **30 days**, **90 days** or **1 year**. An expired key stops working.
  </Step>

  <Step title="Create the key">
    Click **Create key**. The window changes to **Save your API key**.
  </Step>
</Steps>

## Save the key

OnlyX shows the key once, right after you create it. It never shows the key again.

<Steps>
  <Step title="Copy the key">
    Click the copy button next to the key. "Copied." shows.

    <Frame caption="**1** The key is shown only now · **2** The key and its copy button · **3** Done">
      <img className="block dark:hidden" src="https://mintcdn.com/onlyx/k92DfOYEl42ZUgyg/images/help/referrals-and-developers/api-keys/save-your-key-light.png?fit=max&auto=format&n=k92DfOYEl42ZUgyg&q=85&s=060e7d70232b1b445eb1d4d933d00856" alt="The Save your API key window with the shown-once warning, the key (hidden here) with its copy button, and the Done button" width="1440" height="1168" data-path="images/help/referrals-and-developers/api-keys/save-your-key-light.png" />

      <img className="hidden dark:block" src="https://mintcdn.com/onlyx/k92DfOYEl42ZUgyg/images/help/referrals-and-developers/api-keys/save-your-key-dark.png?fit=max&auto=format&n=k92DfOYEl42ZUgyg&q=85&s=e82e57d7b6a37c32fd5b5a0fc77c8e87" alt="The Save your API key window with the shown-once warning, the key (hidden here) with its copy button, and the Done button" width="1440" height="1168" data-path="images/help/referrals-and-developers/api-keys/save-your-key-dark.png" />
    </Frame>
  </Step>

  <Step title="Paste the key somewhere safe">
    Paste the key into a password manager, or into the tool that needs it.

    Anyone who has the key can use your workspace with the access you chose. Do not send it in a chat or an email.
  </Step>

  <Step title="Close the window">
    Click **Done**. The key shows in the list.
  </Step>
</Steps>

**Try it** and **Use it with Claude Code** hold ready-made commands with your key in them, for a developer. To learn how to call the OnlyX API, see [Quickstart](/developers/quickstart) and [Authentication](/developers/authentication).

## Read the list of keys

Each row on the **API keys** card shows:

* The key's name, and the first and last characters of the key. The rest of the key is never shown.
* When it was created, and by whom.
* What it may do: **Full access**, **Read only**, or the names of its permissions.
* Which creators it sees: **All creators**, or the creators' names.
* When it was last used, or "Never used".
* When it expires, or "Never expires".

Two badges need your attention:

* **Expired**: the key has stopped working. It stays in the list until you revoke it.
* **Left the workspace**: the person who created the key has left your team. The key still works. If they should no longer have access, revoke it and create a new one.

<Frame caption="**1** Create API key · **2** What the key may do, and which creators it sees · **3** Revoke">
  <img className="block dark:hidden" src="https://mintcdn.com/onlyx/k92DfOYEl42ZUgyg/images/help/referrals-and-developers/api-keys/keys-list-light.png?fit=max&auto=format&n=k92DfOYEl42ZUgyg&q=85&s=a72b0e1d0a91975ce3835daeb9920fb6" alt="The API keys card with two keys, each with its access and creators, and the pencil and bin buttons" width="1512" height="1028" data-path="images/help/referrals-and-developers/api-keys/keys-list-light.png" />

  <img className="hidden dark:block" src="https://mintcdn.com/onlyx/k92DfOYEl42ZUgyg/images/help/referrals-and-developers/api-keys/keys-list-dark.png?fit=max&auto=format&n=k92DfOYEl42ZUgyg&q=85&s=5760c494925937ab9c94596a70278626" alt="The API keys card with two keys, each with its access and creators, and the pencil and bin buttons" width="1512" height="1028" data-path="images/help/referrals-and-developers/api-keys/keys-list-dark.png" />
</Frame>

## Rename a key

<Steps>
  <Step title="Open the rename window">
    On the key's row, click the pencil. The **Rename API key** window opens.
  </Step>

  <Step title="Change the name">
    In **Name**, enter the new name. Then click **Save**. The message "Key renamed" shows.
  </Step>
</Steps>

Only the label changes. Everything that uses the key keeps working.

## Revoke a key

<Steps>
  <Step title="Open the revoke window">
    On the key's row, click the bin. The **Revoke this API key?** window opens.
  </Step>

  <Step title="Revoke the key">
    Click **Revoke key**. A message confirms that the key was revoked.
  </Step>
</Steps>

Everything that uses the key stops working at once: scripts, tools, and any AI assistant connected with it. You cannot undo this. If you need access again, create a new key.

Revoked keys move to **Revoked keys**, at the end of the card. It shows the last 20.

When OnlyX support helps you in your workspace, they can see your keys. They cannot create, rename or revoke them.

## If something goes wrong

<AccordionGroup>
  <Accordion title="&#x22;This workspace already has 25 active API keys. Revoke one you no longer use first.&#x22;">
    The workspace has reached its limit of 25 active keys. Revoke a key that nothing uses any more, then create the new one. Expired keys do not count toward the limit.
  </Accordion>

  <Accordion title="Create key is greyed out">
    Something is missing. Enter a name first. Then the line next to the buttons says what else is missing, for example "Choose at least one creator."
  </Accordion>

  <Accordion title="I lost the key">
    OnlyX cannot show it again. Revoke the key, then create a new one and save it right away.
  </Accordion>

  <Accordion title="&#x22;Its secret was never shown, so nothing can use it&#x22;">
    The window closed before the key could show. For example, you switched to another Settings tab while the key was being created. Nothing can use that key, but it still counts toward the limit. Revoke it, then create another key.
  </Accordion>

  <Accordion title="&#x22;A key was created but its secret was not shown&#x22;">
    You left Settings while the key was being created. Find the key by its name in the list and revoke it. Then create another key.
  </Accordion>

  <Accordion title="A tool that used a key stopped working">
    Look for the key in the list. If it shows **Expired**, it ran out: create a new key. If it is under **Revoked keys**, someone revoked it. Create a new key and give it to the tool.
  </Accordion>

  <Accordion title="&#x22;The keys could not be loaded.&#x22;">
    OnlyX could not load the list. Click **Try again**.
  </Accordion>

  <Accordion title="I do not see API & MCP in Settings">
    Only owners and admins see **API & MCP**. Ask an owner or admin of your workspace.
  </Accordion>
</AccordionGroup>

## What's next

<Columns cols={2}>
  <Card title="Use OnlyX from Claude, ChatGPT, Cursor or VS Code" icon="sparkles" href="/referrals-and-developers/connect-an-ai-assistant" horizontal />

  <Card title="See and disconnect connected apps" icon="unplug" href="/referrals-and-developers/connected-apps" horizontal />

  <Card title="Authentication" icon="key-round" href="/developers/authentication" horizontal />
</Columns>
