Keys and workspace permissions
Limit each integration's transports, operations, workspaces, IP ranges and spending.
Explicit workspace access
A key may include several workspaces. You can select your personal workspace and organizations where you are currently an owner or administrator. Membership alone does not grant access-management authority.
Each REST request uses X-Ndnci-Workspace to choose one permitted workspace. MCP operations select the workspace in their validated input. NDNCI checks the user's current rights on every operation, so removing organization rights also removes the authority carried by existing grants.
Scopes and Tool operations
Scopes describe the resources an integration may use. You can further restrict a key to an explicit Tool-operation allowlist. A read scope does not authorize execution or uploads.
| Scope | Permission |
|---|---|
workspaces:read | Discover authorized workspaces |
tools:read | Discover authorized Tool operations |
tools:run | Estimate and run permitted operations |
jobs:read | Read job status and output |
jobs:write | Cancel or retry eligible jobs |
queue:read | Read workspace queue capacity |
billing:read | Read credit balances and transactions |
media:read | List media and obtain download URLs |
media:write | Upload workspace media |
usage:read | Read usage counters and budgets |
events:read | Read authorized workspace events |
webhooks:read | Read events and webhook deliveries |
webhooks:write | Manage verified webhook destinations and replay delivery |
Choose REST, MCP, or both when creating a key. A REST-only key cannot authenticate to MCP, and an MCP-only key cannot call REST routes. Create separate keys when the integrations need independent rotation, attribution or budgets.
Optional expiration and IP restrictions
Expiration is optional. A key without an expiration remains usable until revoked, suspended, or deprived of the required workspace rights.
An IP allowlist accepts IPv4 and IPv6 addresses or CIDR ranges. Use the public egress address of the application making the call. An empty allowlist permits any source IP; it does not bypass scopes or other controls.
Rotate and revoke
Copy a new secret when you rotate a key, update the application's secret store, and verify its next authorized request. The previous secret stops authenticating. NDNCI stores a hash of key secrets and never returns an existing secret.
Revocation stops new authenticated operations. A provider request already accepted before revocation can still incur its committed cost; job cancellation explains the financial boundary.
Key creation, rotation, revocation and security suspension produce bounded account notifications. Repeated reads do not generate an email for each request.
Set key and workspace budgets to limit unattended spending.