Skip to main content
The MCP server authenticates with a bearer token - a Less API key. The agent sends it on every request, and all calls run as the user that owns the key, limited to that user’s workspace permissions.

Create an API key

1

Open your API keys

In Less, go to Profile → API Keys.
2

Create a new key

Select Create API key, give it a recognizable name (for example Claude Desktop or ChatGPT) and an expiry date. Then confirm.
3

Copy the key

Copy the generated key and store it somewhere safe. You won’t be able to see it again after you close the dialog.

Use it

Clients send the key as an Authorization header:
When you configure a connector, you’ll usually paste it either as a raw header like the above or into an “API key” / “access token” field. The client guides show exactly where:

Keep it safe

An API key acts on your behalf. Treat it like a password.
  • Don’t share it or commit it to a repository.
  • The key inherits your permissions - including the ability to run assets you can execute. It never grants more than your own access.
  • Create a separate key per client so you can revoke one without affecting the others.
  • Revoke a key any time from Profile → API Keys if it’s no longer needed or may be exposed.
The same API key also works with the REST API.