Manage Keys & ServersUpdate an MCP API key

Update an MCP API key

Rename, rescope, re-limit, or deactivate a key. Rescoping takes effect on the key's next request. Send at least one field.

curl -X PATCH "https://mythic-analytics.gulp.workers.dev/builder/mcp/api-keys/123e4567-e89b-12d3-a456-426614174000" \
  -H "Content-Type: application/json" \
  -H "Authorization: Bearer YOUR_API_TOKEN" \
  -d '{
  "name": "Reporting agent (read-only)",
  "scopes": [
    "people:read"
  ],
  "rate_limit_per_minute": 120,
  "is_active": false
}'
{
  "data": {
    "id": "123e4567-e89b-12d3-a456-426614174000",
    "agency_id": "123e4567-e89b-12d3-a456-426614174000",
    "location_id": "loc_abc123",
    "name": "Reporting agent",
    "key_prefix": "mcp_3f9a1c0b",
    "scopes": [
      "people:read",
      "insights:read"
    ],
    "is_active": true,
    "rate_limit_per_minute": 60,
    "last_used_at": "2024-12-25T10:00:00Z",
    "created_at": "2024-12-25T10:00:00Z",
    "updated_at": "2024-12-25T10:00:00Z"
  }
}
PATCH
/builder/mcp/api-keys/{id}
PATCH
Base URLstring

Target server for requests. Edit to use your own host.

Bearer Token
Bearer Tokenstring
Required

An agency key (ak_). Location secret keys are rejected. Scoped keys (mcp_) are not accepted here (403 not_available_to_scoped_keys).

An agency key (ak_). Location secret keys are rejected. Scoped keys (mcp_) are not accepted here (403 not_available_to_scoped_keys).
Content-Typestring
Required

The media type of the request body

Options: application/json
is_activeboolean

false disables the key without deleting it — reversible, unlike revocation.

Request Preview
Response

Response will appear here after sending the request

Authentication

header
Authorizationstring
Required

Bearer token. An agency key (ak_). Location secret keys are rejected. Scoped keys (mcp_) are not accepted here (403 not_available_to_scoped_keys).

Path Parameters

Body

application/json
namestring
Example:
Reporting agent (read-only)
scopesarray
Example:
["people:read"]
is_activeboolean

false disables the key without deleting it — reversible, unlike revocation.

Example:
false

Responses

dataobject

The raw key is absent — it exists only in the create response.