Skip to content

API keys

An API key lets a tool act on your workspace: the Unreal plugin, the desktop app, an MCP client, a CI job or your own script. Hosted keys start with ph_live_. You manage them on the dashboard’s API keys page at https://app.prophouse.dev/keys.

Most people never create a key by hand. When you select Sign in with browser in the desktop app or the Unreal plugin and approve the request, Prophouse creates a key for that app and hands it over directly. Create keys yourself for MCP clients that do not support device sign-in, scripts and automation.

Every key has one scope.

Scope Allows
write Push, edit, comment, review, check out, pull, and everything read allows. The Unreal plugin needs write to push.
read Search, browse, view details and download. Any request that changes the library is refused with a 403 saying the key is read-only.

A key acts with the current workspace role of the person who created it. Admin-only actions work only with keys created by an owner or admin, demoting someone from admin demotes their keys too, and removing someone from the workspace disables every key they created.

Device sign-in from the desktop app and the Unreal plugin always requests write, and the approval page shows the scope before you approve.

  1. Open API keys on the dashboard.

  2. Under Create key, enter a Name that says where the key will live, for example workstation-ue5 or ci-nightly.

  3. Choose a Scope: write (the default) or read.

  4. Select Create key.

  5. Copy the key from the Key created panel. It is shown once and cannot be shown again, because Prophouse stores only a hash of it.

Send the key as a bearer token:

Terminal window
curl "https://api.prophouse.dev/api/v1/entries?q=wooden+crate" \
-H "Authorization: Bearer ph_live_xxxxxxxxxxxx"

For MCP clients, the Connect MCP panel on the API keys page shows a ready-made configuration:

{
"mcpServers": {
"prophouse": {
"url": "https://api.prophouse.dev/mcp",
"headers": { "Authorization": "Bearer <your key>" }
}
}
}

See AI agents (MCP) for per-client setup and REST API for the endpoints.

The Keys table lists each key’s Name, the first characters of the Key, its Scope and when it was Last used. Keys created by device sign-in are named after the app, for example Prophouse desktop (device sign-in) or Unreal Editor on WORKSTATION-07 (device sign-in).

The Usage page breaks this month’s traffic down By API key.

Select Revoke next to the key. Revocation takes effect on the key’s next request, which fails with Unknown or revoked API key. There is no undo; create a new key if you need one again.

Revoke a key when a machine is retired, a contractor leaves, or you suspect the key was exposed. To sign an app back in after revoking its key, use Sign in with browser again.