Authentication
Two ways in, both carrying a person.
API keys
Made in Settings → Connections, scoped to what you choose, and tied toyou. Send it as a bearer token.
Authorization: Bearer dva_live_…A key is shown once. If it leaks, revoke it in the same place: revocation is immediate.
A key expires after 90 days unless you choose otherwise when you make it. Over the API, leave expiresInDays out for the default, send a number of days up to 365, or send null for a key that lasts until you revoke it.
Keys are made and revoked by a person signed in to a browser. A key, or an agent connected by OAuth, cannot make another key or revoke one, and neither operation is offered as an MCP tool. That way a key that leaks can be revoked and stays revoked.
A builder key acts in one organisation, the one you pick when you make it. It cannot reach your other organisations, even though you can.
OAuth, for agents
An MCP client signs in through the browser and receives a token bound to the person who approved it. That is why an agent connected by a Support user cannot read what Support cannot read: there is no other identity for it to borrow.
The consent screen shows where the client will send its answer, next to the name the client gave itself. Check that address before you approve. On the Studio, the connection is also bound to the one organisation you choose on that screen.
Scopes
The same names on both sides: an app's own keys, and the Studio's builder keys.
| Scope | Lets a credential |
|---|---|
records:read | read rows, their comments and history, SQL reads, your saved views, the change history |
records:write | create, update and delete rows, comment, upload files, undo |
schema:read | read tables, fields and rules |
schema:write | change tables, fields and rules (Studio only) |
pages:read / pages:write | read, save and publish pages: an app's in the Studio, your own in an app |
members:read / members:write | see and manage who is in an app and the directory |
account:read | see organisations, suites, apps, plan and usage (Studio only) |
account:write | start, leave or delete an organisation, close your account (Studio only) |
Scopes narrow a credential; they never widen it. A key with records:write made by someone who may only read still cannot write.
Check what you are holding
curl "https://acme.gtable.app/crm/v1/me" -H "Authorization: Bearer $DUVAPPS_TOKEN"