Managing MCP client credentials and API keys
The Client IDs & API keys card — in the AI client credentials section at the bottom of the MCP Setup page (/endpoints) — is where you create and manage machine credentials for AI tools and automation…
Written By Christopher Scaminaci
Last updated 6 days ago
The Client IDs & API keys card — in the AI client credentials section at the bottom of the MCP Setup page (/endpoints) — is where you create and manage machine credentials for AI tools and automation platforms that cannot use browser sign-in. Each credential shows as its own row with a Create Client and Create API Key button in the card header.
Who can manage credentials: the account owner, co-owners, and Administrators. Members can view the page, but the create/edit/rotate/revoke actions are hidden from them.
The credentials list
Each credential appears as its own row showing:
The Edit Roles, Edit Tools, Rotate Secret, and Revoke actions appear on each active row for users who can manage credentials. Once a credential holds a role, the tools button is relabelled Edit Extras — the credential's own tool list becomes a set of extras added on top of its roles.

Create a Client ID + Secret
- Open MCP Setup and select Create Client.
- Step 1 — Name it. Use something that identifies the tool and purpose (for example "Cline — Alice's laptop").
- Step 2 — Pick allowed tools. The tool selector defaults to every connector tool your plans include. Trim the selection if the credential should be narrower. (StackJack platform tools, such as the support-ticket tools, are always available to any connection and aren't part of this selection.) An empty selection is refused here — "Please select at least one tool."
- Select Create. A Client Created dialog shows the Client ID and the secret with copy buttons.
- Copy the secret now. It is displayed this one time only — it is stored as a one-way hash and can never be shown again. If you lose it, the only recovery is rotation.
There is no role picker during creation. The create flow is just those two steps — name, then tools. Attach tool roles afterwards with Edit Roles on the credential's row.
The tool then authenticates with an HTTP Basic header:
Authorization: Basic <base64 of CLIENT_ID:CLIENT_SECRET>
Create an API key
API keys are single-value credentials (sjk_...) for automation platforms (n8n, Make, Power Automate, Zapier, webhooks).
- Select Create API Key.
- Step 1 — Name it and accept the risk. Enter a name (for example "n8n Automation"), read the security considerations, then type the phrase "I accept the risk" — you cannot continue until both are done. The acknowledgment is recorded (who accepted, when, and a fingerprint of the key). The guidance to follow:
- An API key grants the same access as a Client ID + Secret in a single copyable value.
- Never commit it to source control; store it in environment variables or a secrets manager.
- Prefer Sign in with StackJack or Client ID + Secret for interactive AI tools.
- Step 2 — Pick allowed tools (same selector as clients).
- The full key is displayed once, with both ready-to-copy usage forms:
X-API-Key: sjk_...Authorization: Bearer sjk_...
Edit a credential's roles and tools
Select Edit Roles on any active row to attach or remove tool roles — reusable bundles defined on the Roles page. Select Edit Tools to reopen the tool selector and change what that credential may call directly. Changes apply to the credential immediately.
Once a credential holds a role, the second button reads Edit Extras: its own tool list is now a set of extras layered on top of everything its roles grant. That also changes what an empty selection means. Saving nothing is refused on a credential with no roles ("Please select at least one tool") — that would leave a dead credential. Saving nothing is accepted on a role-bearing credential, because its access comes from the roles.
Scope note: the organization-level credentials on this page carry their own tool set and nothing else — the secret does not identify who is using it, so whoever holds it gets the credential's full effective tools (its roles plus its extras). The overlap rule ("most restrictive wins") applies only to a credential linked to a person — a member credential on the Team page — where a member or Administrator is narrowed to the intersection of their own effective tools and the credential's; an owner or co-owner is not narrowed by the member side. To scope an org-level credential, narrow the credential itself.
Rotate a secret or API key
Rotate when a secret may have been exposed, or when you lost it and need a new one.
- Select Rotate Secret (for API keys, the confirmation again requires typing "I accept the risk").
- Confirm. The old secret stops working immediately.
- The new secret or key is shown once, in the same one-time dialog as at creation. Update the tool with the new value.
What rotation cuts off. Rotation retires the old secret and every OAuth access and refresh token minted from it. A tool still holding an old token gets a 401 on its next request, and a refresh attempt with an old refresh token is refused. There is no grace window.
What rotation leaves alone. The credential itself stays active, so the AI tool is not revoked — it is simply holding a secret that no longer works. Paste the new secret into the tool to bring it back. In short: rotation replaces the secret and cuts the tokens made from it; revocation ends the credential. Use Revoke when the credential should never work again.
Whenever a credential is rotated or revoked, StackJack emails the account owner a security confirmation of the change.
Revoke a credential
- Select Revoke on the row and confirm. The dialog warns: any AI agents using these credentials will stop working immediately.
- Revocation is immediate and covers every way the credential could be used — Basic auth, API-key headers, OAuth tokens minted from it, and token refresh.
Revocation is permanent: there is no reactivate button in the portal. Revoked rows are hidden by default — the card header shows an N active count badge and, once any credential is revoked, a Show revoked toggle; tick it to reveal the revoked rows (retained with a Revoked badge for your records). If the tool needs access again, create a new credential.
Member credentials (on the Team page)
The credentials on this page are organization-level — shared across your team for tools that can't sign in, and created by you here. There is a separate, second kind: member credentials — the personal Client ID + Secret pairs minted automatically when a team member signs in with their own StackJack account and connects an AI tool on Connectors (/connectors). There is no create step for them.
Member credentials do not appear on this page. On the Team page (/team), expand a member's row in Active Members (the chevron) to see and manage their connections under Member credentials — owners, co-owners, and Administrators can Rotate Secret or Revoke any member's connection there. (If your subscription has lapsed, these move to a standalone Member credentials card on the Team page, so a manager keeps rotate/revoke on connections minted before the lapse.)
A member credential's tool access is shown read-only on that card, as a plain count of the tools stored on that credential itself. Adjust access from the member's own row in Active Members, which is where both levers live: Edit Roles to assign tool roles, and Edit Tools — relabelled Edit Extras once the member holds a role — for tools picked for them individually. What the member can actually call through the credential is the overlap of their own effective tools (their roles plus their extras) and the credential's, so the read-only count on this card is not the whole answer on its own. See Managing members.
Related pages
- How AI tools authenticate — when to use each credential type.
- OIDC sessions and revoking AI access — the full revocation playbook, including sign-in-based connections.