# API keys and OAuth

> How mmw_ keys work, how to reveal, rotate and revoke them, how a key limits an agent to one project, and how claude.ai and ChatGPT sign in without your key.

By the end of this page you will know:

1. how to get, store, rotate and revoke an API key;
2. how a key limits an agent to a single project;
3. how to connect claude.ai and ChatGPT over OAuth without handing them your key;
4. what to do if the email verification message does not arrive.

## Email verification

1. Sign up at [app.mmwhub.tech](https://app.mmwhub.tech/signup). Two checkboxes are required: consent to personal data processing, and acceptance of the terms and privacy policy.

2. Open the email from `noreply@mmwhub.tech` and follow the link. The account shows "Email verified".

3. No email? Check your spam folder. You can request it again with "Send the email again" on the Organizations page, at most once a minute.

A verified email is required, among other things, to accept an invitation to an organization.

## API key

A key is how your agent proves it acts on your behalf. Its properties:

| Property | Value |
|---|---|
| Format | Starts with `mmw_` |
| How it is sent | `Authorization: Bearer mmw_…` header, or the `MMW_API_KEY` variable for mmw-agent. Never in a URL |
| Display | The secret is shown **once** |
| Server storage | Only a PBKDF2 hash plus a lookup index; the plain key is not kept on the server |
| Revocation | Immediate: the next call with that key gets `401` |

### Personal key

In the account, under "API Token & Access":

| Button | What it does |
|---|---|
| "Reveal" | Shows the secret once. After that: "Already revealed. Rotate to generate a new secret." |
| "Rotate" | Revokes the current key and creates a new one; the new secret can also be revealed once |
| "Revoke" | Disables the key. Issue a new one to keep working |

### Organization keys

In an organization, every person issues a key for themselves on the Keys tab; the admin sees and revokes keys but can never reveal them. See [Invitations and keys](/organizations/invitations-and-keys/).

A key gives access to memory. Do not paste it into assistant chats, tickets, Git, screenshots or support emails. If a key leaks, click "Rotate" or "Revoke" right away and put the new key into your clients.

## Keys and projects

An account is split into projects, and a project into workspaces. A key can be bound to a project: an agent using it sees only that project's records and cannot work with another project's workspaces. A key created by "Rotate" is bound to the default project.

This is a simple way to separate, say, a work project from personal notes: two clients, two keys, two independent memories. See [Workspaces and projects](/memory/workspaces-and-projects/).

## OAuth: claude.ai and ChatGPT

Web assistants cannot run the local agent and do not keep your key in a config file. They connect to MMW over OAuth: you approve access once on an MMW page, and the assistant receives **its own token valid for 30 days**. Your API key is never shared with the assistant.

1. Settings → Connectors → Add custom connector.
2. URL: `https://mcp.mmwhub.tech/mcp`.
3. On the MMW page, paste your API key and click Allow.

See [claude.ai](/clients/claude-web/).

1. Turn on Developer mode and add a connector with the URL `https://mcp.mmwhub.tech/mcp`.
2. The MMW consent page opens.
3. Sign in with your MMW account email and password, or with an API key, and approve access.

ChatGPT support is in beta. See [ChatGPT](/clients/chatgpt/).

```text
  claude.ai / ChatGPT           MMW
  ───────────────────           ───
  "add connector"         →     consent page: you enter a key or password
                          ←     the assistant gets its own 30-day token
  remember / search call  →     token is checked; the assistant never saw your key
```

When an assistant no longer needs access, remove the connector in its settings. If you entered an API key on the consent page and are unsure it stayed safe, rotate the key in the account.

## Common problems

| Symptom | Cause | What to do |
|---|---|---|
| `401` on every call | Key revoked, rotated or copied incompletely | Copy the current key; rotate if needed |
| "Already revealed" when revealing | The secret is shown only once | "Rotate" creates a new key; the old one stops working |
| The agent does not see records saved from another client | The keys are bound to different projects | Use a key for the same project |
| "An email was sent recently" | Resent more than once a minute | Wait a minute |

## Next steps
