My Account

API Keys

Create and manage API keys for programmatic access to DevStride, and — for administrators — view and revoke every member's keys across the organization.

API keys let you (and the tools you connect) talk to DevStride programmatically — through the API and integrations such as the DevStride MCP server. Each key is tied to the member who created it and carries that member's access.

Where to find them

Open Settings → My Account → API Keys (the key icon). The page lists your keys and has a Documentation link to the full API reference.

Creating a key

  1. Open the create dialog and give the key a label so you can recognize what it's for.
  2. Generate it. The secret is shown once, with a Copy action.
  3. Copy the secret and store it somewhere safe — it can't be retrieved again. After this, the list shows only the key's public identifier, never the secret.

Managing your keys

From the keys table you can edit a key's label or delete (revoke) a key you no longer need. Revoking a key stops it working immediately, so any tool using it will need a new one.

Org-wide key management (administrators)

Roles with the Manage all API keys permission see an extra section, All Organization API Keys, listing every member's keys across the organization — so an administrator can audit what's in use and revoke any key immediately (for example, when someone leaves). As everywhere, only the public identifier is shown; secrets are never exposed after creation.

Suspending a member cuts off their keys too. A key belonging to a suspended membership no longer authorizes requests against your organization — you don't need to hunt down and revoke each key individually. Allow a few minutes for the change to take effect.

How permissions work

  • Creating and managing your own keys is available to any role with the create-API-keys permission — the default Member and Admin roles have it.
  • Viewing and revoking everyone's keys requires the Manage all API keys administrative override (the default Admin and Owner roles). Without it, you only see and manage your own keys.

See Roles & Permissions for how these capabilities are assigned.

Rate limits

Each organization's API keys and MCP connections share one budget of 1,000 requests per minute. Requests over it are refused with HTTP 429 Too Many Requests, a Retry-After header giving the seconds until the minute resets, and a JSON body whose code is AUTH.ORGANIZATION_RATE_LIMIT_EXCEEDED and whose metadata carries limitPerMinute, retryAfterSeconds and windowResetsAt. Wait for the reset before retrying — a retry sooner is refused again. The DevStride MCP passes the wait on in its tool error, so an AI agent backs off by itself. Using DevStride in the browser never counts against the budget. If your integration needs more, contact support.

Vocabulary changes in the API and MCP tools

The app has said Status and Workstream for a while; the API, the generated SDKs, the real-time events and the MCP tools now use the same words. Each rename ships with a compatibility window: the old names keep working until the date below, and responses to the old paths carry standard Deprecation and Sunset headers plus a Link header naming the replacement, so you can find affected calls programmatically.

Old nameNew nameOld names removed on
lane — laneId and other lane* keys, /lanes… paths, *_lane MCP toolsstatus2026-10-31
folder — folderNumber and other folder* keys, /folders… paths, *_folder MCP tools, folder-* real-time eventsworkstream2026-10-01

Until its date, a request may send either spelling (when both are present, the new one wins) and a response carries both. Anything that reads the old keys, calls the old paths or tools, or binds the old real-time event names should move before that date. Board folders in Plan Delivery are not part of this rename and keep their name.