> Content index: https://quillly.com/docs/llms.txt
> Canonical page: https://quillly.com/docs/api-keys

---
title: Quillly API Keys, OAuth and Tool Access
description: Create, rotate and revoke Quillly API keys on Connections, choose the tools each key can use, manage OAuth connections and check your limits.
keywords: API keys, OAuth connection
published: 2026-09-24
updated: 2026-09-25
url: https://quillly.com/docs/api-keys
word_count: 1030
---

# API keys, OAuth and tool access

> Create, rotate and revoke Quillly API keys on Connections, choose the tools each key can use, manage OAuth connections and check your limits.

Canonical: https://quillly.com/docs/api-keys
Published: 2026-09-24

## Related Pages

- [Connect your AI](https://quillly.com/docs/connect-your-ai)
- [Connect Claude](https://quillly.com/docs/connect-claude)
- [Plan limits and allowances](https://quillly.com/docs/limits)
- [Plans, trial and limits](https://quillly.com/docs/plans)
- [MCP tool reference](https://quillly.com/docs/mcp-tools)

The **Connections** page controls how AI apps reach your Quillly account. On it you create, rotate and revoke API keys, choose the tools each key can use, manage OAuth connections, and check your daily usage and limits.

![The Connections page in Quillly, listing two API keys and one OAuth connection, with the Connect button highlighted](https://quillly.com/serve/v1/019c64a2-a62f-7793-aa68-2c78316d3309/images/48ed5f7e671aa7a949a3c2b528e427de28a50aa6.webp)

## What the Connections page shows

Open **Connections** under **Configure**. **AI assistant usage** sits at the top, and **Your connections** lists one line per API key or OAuth connection.

Each line shows the connection's name, an **API key** or **OAuth** badge, when it connected and was last used, how many tools it has, and its calls this week. The line above the list shows your keys against your plan's limit, the calls allowed per minute, and the number of tools on your plan.

[Open Connections](https://quillly.com/dashboard/connections)

## Create API keys

### 1. Click Connect

On **Connections**, click **Connect**. When you reach your plan's key limit, the button is hidden: revoke a key you no longer use to make room.

### 2. Name the key and create it

Name the connection after where it is used, such as `Work laptop` or `Weekly post routine`, and click **Create**.

### 3. Copy the snippet for your app

The setup dialog opens with the key already in each snippet. Pick your app, click **Copy** and paste the snippet into the app, as its [connection page](https://quillly.com/docs/connect-your-ai) shows.

After you close the dialog, Quillly shows only the start of the key, such as `qly_8f3k2a1c`. A new key starts with every tool on your plan switched on, and it works until you rotate or revoke it.

## Choose a key's tools

Click a key's name to open it. **Enabled tools** lists each tool under **Read**, **Write** or **Analytics**, with a switch. Switch a tool off, and the AI using this key can no longer call it. If it tries, Quillly tells it the tool is off for this connection and where to turn it back on.

![A key's page on Connections with the Enabled tools list, showing Delete Content switched off](https://quillly.com/serve/v1/019c64a2-a62f-7793-aa68-2c78316d3309/images/9de443449b10c1c904cad7bde898db81bc7cc028.webp)

- **New tools start switched on.** When Quillly adds a tool, it is on for your existing keys too. A tool you switched off stays off.

- **A badge such as Off for writers** means your organization turned the tool off for your role. You cannot switch it on from here.

- **OAuth connections have no switches.** They always get every tool on your plan.

> [!NOTE]
> Switches decide which tools a key can call, not what a tool may do. **Create Content** can save a new post as published, so switching off **Publish Content** alone does not stop an AI from publishing.

## Rotate a key

Rotate a key when you lose it or think it leaked. Click **Rotate key** on its line, or inside the connection, and confirm. The new key appears once in the setup dialog, and the connection keeps its name and its tools.

> [!WARNING]
> Rotating or revoking a key cuts off every app that uses it, at once. Paste the new key into those apps right after you rotate.

## Revoke a key or an OAuth connection

Click **Revoke** and confirm. A revoked key stops working at once and leaves the list for good. Revoking an OAuth connection removes that app's access, and the app has to sign in again to reconnect.

## OAuth connections

Some apps can connect with OAuth instead of a key. You paste the plain server URL, `https://quillly.com/api/mcp`, and the app sends you to Quillly to sign in.

The first time an app asks, Quillly shows a screen titled **Authorize** with the app's name. It lists what the app may do: read and write your content, publish on your connected sites, and read your search and analytics data. Click **Allow access** to connect, or **Cancel** to refuse. The connection then appears on **Connections** with an **OAuth** badge.

We recommend a key instead. OAuth completes only in a browser where you are signed in to Quillly, so it fails in a terminal, on a server or on someone else's computer. Use OAuth where a key would be shared with other people, such as a connector for a whole [Claude organization](https://quillly.com/docs/connect-claude). In the setup dialog, it sits under **Prefer OAuth?**.

## Usage and limits

![The AI assistant usage panel on Connections, showing requests today against the daily limit, 14 days of calls, top tools and calls by connection](https://quillly.com/serve/v1/019c64a2-a62f-7793-aa68-2c78316d3309/images/96ea78c80673bbe9a8668eeffcd6ce04f2615941.webp)

**AI assistant usage** shows today's requests against your [daily limit](https://quillly.com/docs/limits), your calls over the last 14 days, today's top tools, and each connection's calls over those 14 days.

- **One daily limit covers all your connections**, and it resets at midnight UTC.

- **There is also a per-minute limit**, shown above your connections.

- **Only calls that succeed count.** Calls that fail or are refused cost nothing.

- **At a limit, nothing runs.** Quillly answers your AI with the time the limit resets.

| Plan | API keys | Calls a day | Calls a minute |
| --- | --- | --- | --- |
| Pro | 5 | 1,000 | 60 |
| Autopilot Starter | 10 | 2,000 | 60 |
| Autopilot Pro | 20 | 4,000 | 100 |
| Autopilot Scale | 50 | 10,000 | 200 |
| Analytics 10k | 3 | 500 | 30 |
| Analytics 100k | 5 | 1,000 | 60 |
| Analytics 500k | 10 | 2,000 | 60 |
| Analytics 2M | 20 | 4,000 | 100 |

The trial uses Pro's limits. [Plans, trial and limits](https://quillly.com/docs/plans) covers what else each plan includes.

## Keys on a team

Keys belong to the person who creates them, so each teammate creates their own on their own **Connections** page. On a website someone shared with your organization, the organization's **Agent tools** settings also apply: a tool turned off there for your role stays off, whatever your key allows.

## Common questions

### I lost my key. Can I see it again?

No. Quillly stores keys hashed, so it cannot show one again, not even to you. Rotate the key to get a new one: the connection keeps its name and its tools, and only the key changes.

### What is the key called Onboarding key?

Onboarding creates it when you connect your AI there. It works like any other key, and you can open it, change its tools, rotate it or revoke it on this page.

### Do keys expire?

No. A key works until you rotate or revoke it, so check the list now and then and revoke keys you no longer use.

## Related

- [Connect your AI](https://quillly.com/docs/connect-your-ai): the apps you can use and the one way we recommend.

- [Connect Claude](https://quillly.com/docs/connect-claude): the connector, and OAuth for Team and Enterprise plans.

- [Plans, trial and limits](https://quillly.com/docs/plans): what each plan includes.

- [MCP tool reference](https://quillly.com/docs/mcp-tools): what each tool does, and the team role it needs.
