DDuvappsDocumentationStudio

Authentication

Two ways in, both carrying a person.

API keys

Made in Settings → Connections, scoped to what you choose, and tied toyou. Send it as a bearer token.

Authorization: Bearer dva_live_…

A key is shown once. If it leaks, revoke it in the same place: revocation is immediate.

A key expires after 90 days unless you choose otherwise when you make it. Over the API, leave expiresInDays out for the default, send a number of days up to 365, or send null for a key that lasts until you revoke it.

Keys are made and revoked by a person signed in to a browser. A key, or an agent connected by OAuth, cannot make another key or revoke one, and neither operation is offered as an MCP tool. That way a key that leaks can be revoked and stays revoked.

A builder key acts in one organisation, the one you pick when you make it. It cannot reach your other organisations, even though you can.

OAuth, for agents

An MCP client signs in through the browser and receives a token bound to the person who approved it. That is why an agent connected by a Support user cannot read what Support cannot read: there is no other identity for it to borrow.

The consent screen shows where the client will send its answer, next to the name the client gave itself. Check that address before you approve. On the Studio, the connection is also bound to the one organisation you choose on that screen.

Scopes

The same names on both sides: an app's own keys, and the Studio's builder keys.

ScopeLets a credential
records:readread rows, their comments and history, SQL reads, your saved views, the change history
records:writecreate, update and delete rows, comment, upload files, undo
schema:readread tables, fields and rules
schema:writechange tables, fields and rules (Studio only)
pages:read / pages:writeread, save and publish pages: an app's in the Studio, your own in an app
members:read / members:writesee and manage who is in an app and the directory
account:readsee organisations, suites, apps, plan and usage (Studio only)
account:writestart, leave or delete an organisation, close your account (Studio only)

Scopes narrow a credential; they never widen it. A key with records:write made by someone who may only read still cannot write.

Check what you are holding

curl "https://acme.gtable.app/crm/v1/me" -H "Authorization: Bearer $DUVAPPS_TOKEN"