https://app.mapxagent.com?open=api-keys (or app → Profile/Account → API Keys).
The raw key (for example mkx_...) is shown only once, so save it immediately.
The backend stores only a SHA-256 hash of the key. If a key is leaked, revoke it
from your account and create a new one.
API requests
Send the key as a bearer token:CLI requests
Save the key locally once, then let the CLI reuse it:mapx auth login stores the key in ~/.mapx/config.json (0600 permissions);
mapx auth logout removes it. Environment variables remain supported as a
fallback:
--api-key and --url overrides. All operations are
scoped to the account that owns the key, and project ownership is enforced by
the backend.
