Skip to content

API keys and OAuth

By the end of this page you will know:

  1. how to get, store, rotate and revoke an API key;
  2. how a key limits an agent to a single project;
  3. how to connect claude.ai and ChatGPT over OAuth without handing them your key;
  4. what to do if the email verification message does not arrive.
  1. Sign up at app.mmwhub.tech. Two checkboxes are required: consent to personal data processing, and acceptance of the terms and privacy policy.

  2. Open the email from noreply@mmwhub.tech and follow the link. The account shows “Email verified”.

  3. No email? Check your spam folder. You can request it again with “Send the email again” on the Organizations page, at most once a minute.

A verified email is required, among other things, to accept an invitation to an organization.

A key is how your agent proves it acts on your behalf. Its properties:

PropertyValue
FormatStarts with mmw_
How it is sentAuthorization: Bearer mmw_… header, or the MMW_API_KEY variable for mmw-agent. Never in a URL
DisplayThe secret is shown once
Server storageOnly a PBKDF2 hash plus a lookup index; the plain key is not kept on the server
RevocationImmediate: the next call with that key gets 401

In the account, under “API Token & Access”:

ButtonWhat it does
“Reveal”Shows the secret once. After that: “Already revealed. Rotate to generate a new secret.”
“Rotate”Revokes the current key and creates a new one; the new secret can also be revealed once
“Revoke”Disables the key. Issue a new one to keep working

In an organization, every person issues a key for themselves on the Keys tab; the admin sees and revokes keys but can never reveal them. See Invitations and keys.

An account is split into projects, and a project into workspaces. A key can be bound to a project: an agent using it sees only that project’s records and cannot work with another project’s workspaces. A key created by “Rotate” is bound to the default project.

This is a simple way to separate, say, a work project from personal notes: two clients, two keys, two independent memories. See Workspaces and projects.

Web assistants cannot run the local agent and do not keep your key in a config file. They connect to MMW over OAuth: you approve access once on an MMW page, and the assistant receives its own token valid for 30 days. Your API key is never shared with the assistant.

  1. Settings → Connectors → Add custom connector.
  2. URL: https://mcp.mmwhub.tech/mcp.
  3. On the MMW page, paste your API key and click Allow.

See claude.ai.

claude.ai / ChatGPT MMW
─────────────────── ───
"add connector" → consent page: you enter a key or password
← the assistant gets its own 30-day token
remember / search call → token is checked; the assistant never saw your key
SymptomCauseWhat to do
401 on every callKey revoked, rotated or copied incompletelyCopy the current key; rotate if needed
“Already revealed” when revealingThe secret is shown only once“Rotate” creates a new key; the old one stops working
The agent does not see records saved from another clientThe keys are bound to different projectsUse a key for the same project
“An email was sent recently”Resent more than once a minuteWait a minute