ContentStudio
Dark mode
Authentication and API Keys

Authentication and API Keys

ContentStudio’s REST API and CLI use an API key to authenticate requests. Treat API keys as secrets with the same care as a password.

Create a key

  1. In ContentStudio, open the main API module.

  2. On the API tab, generate a new key.

  3. Copy it immediately and store it securely.

Use distinct keys for separate environments or integrations when your operating model permits it. This makes rotation and incident response safer.

Use a key with the REST API

Send the key in the X-API-Key request header:

curl -H "X-API-Key: $CONTENTSTUDIO_API_KEY" \
  https://api.contentstudio.io/api/v1/me

For endpoint parameters, request bodies, responses, and errors, use the ContentStudio API Reference.

Use a key with the CLI

For local development:

contentstudio auth:login --api-key cs_your_api_key_here

For CI and services, provide the key through a secure service environment:

export CONTENTSTUDIO_API_KEY=cs_your_api_key_here

Use a key with MCP

Prefer OAuth where your MCP client supports it. If OAuth is unavailable, configure the key only in the client’s protected connection settings. Regenerating a key requires updating each configuration that uses it.

Rotate or revoke a key

If a key is exposed, open the main API module and regenerate or revoke it immediately. Replace it in every integration, then verify each integration before removing the old configuration.

Security checklist

  • Never place a key in frontend code, browser storage, public repositories, screenshots, or chat messages.

  • Use environment variables or a secret manager for automated workloads.

  • Limit access to the systems and people that need the key.

  • Remove unused keys and integration configurations.

  • Recheck connected MCP clients, CLI services, and OpenClaw services after rotation.

Troubleshooting

  • 401 Unauthorized: verify that the correct key is present in the request header or service environment.

  • 403 Forbidden: verify that your account has API access and that the key can access the requested workspace resource.

  • A background service cannot authenticate: update the service’s own environment and restart it. Changing a shell variable is not enough.

  • An MCP connection broke after a key change: update or reconnect the MCP client.

Verification

API keys are created and managed from the main API module. Use the API tab to generate, rotate, or revoke a key.

Was this article helpful?