Create a key
- In Heralded, open Settings, choose You, then API keys, and choose Create API key.
- Name the key after what will use it, such as
LookerorWeekly export. - Pick the workspace or organization, when you belong to more than one. A key reads one.
- Pick when it expires: 30 days, 90 days, 1 year or never. The default is 90 days.
- Copy the key. It starts with
hrld_, and Heralded shows it only once and stores only a hash of it.
Use a key
Send the key as a bearer token on every request:Authorization and its value is Bearer hrld_.... The MCP guide shows the setup for common MCP clients.
Treat a key like a password. Keep it in a secret store or an environment variable, not in code or a shared document.
What a key can read
- The brands you can read in the key’s workspace, as
GET /v1/brandslists them. - Your access is checked again on every request. If a role or grant changes, the key reads what you can read now.
- A brand outside the workspace, or one you can no longer read, answers
404 not_found, the same as a brand that does not exist. - Once the workspace is archived, every REST request answers
409 workspace_archived, and an MCP tool call returns it as an error result; see Errors over MCP.
Revoke a key
The API keys page lists each key with its workspace, when it was created, when it was last used and when it expires. Revoke deletes the key, and its next request answers401 invalid_token. An expired key answers the same way. A revoked or expired key cannot be restored; create a new one.