MCP automation keys are a limited-availability feature in partner beta. Thread
enables them per workspace. Contact your Thread representative or CSM if you’d
like them turned on for your workspace. Until then, requests that issue a key
for another member return a 403 error.
- Thread MCP is enabled for your workspace. See the Thread MCP server developer guide.
- MCP automation keys are enabled for your workspace (see the note above).
- You are a workspace admin or team admin. Non-admins can only create keys for themselves.
- The member the key will act as has an active seat in your workspace.
Decide which member the key should act as
The key inherits the bound member’s exact Thread permissions. Pick the member whose access matches what the automation needs, and nothing more:- A read-only reporting job should bind to a member without write access.
- An automation that creates tickets needs a member who can create tickets in Inbox.
Issue the key in Thread Admin
When MCP automation keys are enabled for your workspace, workspace admins and team admins see an MCP keys page under Magic AI in the Thread Admin navigation:- Open Admin → Magic AI → MCP keys.
- Select Generate token.
- Pick the member the key acts as, give the key a name (for example
n8n production), and set an expiry. The expiry defaults to 90 days and can be at most one year out. - Select Create. Thread shows the key in plaintext exactly once, along with copy-ready setup snippets for Claude Code, Claude Desktop, Cursor, and a cURL verification call. Copy the key immediately and store it in your secrets manager; Thread keeps only a hash.
Issue the key with the API
You can also send aPOST request to /api/v1/mcp/tokens on the Thread API, authenticated as your own admin account:
name, a label for the key (1–100 characters). Name it after the automation that will use it, not the person.expires_at— when the key stops working. Required when issuing for another member, and it must be within one year. Requests without an expiry, or with one more than a year out, are rejected.member_id, the Thread member the key acts as. The member must belong to your workspace and be active; ids from outside your workspace fail validation. Omitmember_idto create a key for yourself.
Use the key in your automation
MCP automation keys start withmcp_ and work as a standard bearer token against the Thread MCP endpoint:
mcp_YOUR_KEY_HERE with the plaintext key you copied when it was issued. The tools/list call is a safe way to confirm the key works: it returns the Thread tools the bound member can use without changing anything.
In an automation platform, paste the key wherever the MCP or HTTP connection asks for a bearer token, with https://api.getthread.com/mcp as the server URL. Rate limits are shared with OAuth connections in the same workspace; see rate limits in the developer guide.
Review and revoke keys
- Every key stores who issued it and when it was last used, so you can audit which admin created which credential and spot stale keys.
- The MCP keys page in Thread Admin lists the keys you can manage. Select Revoke next to a key and confirm to disable it.
- With the API, add
?scope=companyto aGET /api/v1/mcp/tokensrequest to list keys beyond your own. Workspace admins see every key in the workspace. Team admins see keys bound to members on their teams, plus their own. Non-admins who request?scope=companyget a 403 error. Without the parameter, you see only your own keys. - Revoke a key with
DELETE /api/v1/mcp/tokens/{id}. Workspace admins can revoke any key in the workspace. Team admins can revoke keys bound to members on their teams, plus their own. Everyone else can revoke only their own keys. A key outside your scope returns a not-found error, so revoking it never confirms that it exists. Revocation is immediate, and revoking an already-revoked key returns an error rather than silently succeeding. - Keys stop working the moment they expire or are revoked. If Thread disables MCP automation keys for a workspace, keys issued for another member stop authenticating immediately; self-issued keys keep working.