Skip to main content
An application gives automation, CI/CD pipelines, and other tools access to Oplane’s API and MCP server without using a person’s login. Each application has its own identity and permissions, and one API key that you can regenerate at any time.
You need the Org Admin role to create and manage applications. See Roles and permissions.

Create an application

Open the organisation switcher in the top-right corner and click Org Settings. Then open the Application tab and click New application.
1

Name the application

Enter an Application name of up to 64 characters. Pick a name that tells your team where the key is used, for example GitHub Actions - prod deploys.
2

Set when the key expires

Under API key expiration, pick 7, 14, 30, 60, or 90 days, or choose Custom… to set a date up to 365 days ahead. The default is 30 days.
3

Choose workspace access

Under Workspace access, choose All workspaces to include every current and future workspace in the organisation, or Only selected workspaces and pick the ones the application can reach.
4

Set permissions

Under Permissions, set each area to No access, Read, or Read & Write. See Permissions below for what each area covers.
5

Create and copy the key

Click Create application. Oplane shows the API key once, under the new application in the list. Click Copy and store the key in a secret manager, such as your CI provider’s secrets.
Oplane stores only a hash of the key, so you can’t see it again after you leave the page. If you lose it, regenerate the key. Anyone with the key has the access you granted until it expires.

Permissions

Both Contents and Organization administration start at No access. Grant only what the tool needs. For example, a pipeline that reads requirements needs Read on Contents and nothing else. Organization administration never lets an application manage other applications or their keys, even at Read & Write.

Use the key

Application keys start with oak_v1_. To connect to the Oplane MCP server, send the key as a bearer token in the Authorization header:
Keep the key out of files you commit. If your MCP client or CI tool can read values from an environment variable or a secret, use that instead. For Oplane’s REST API, send the key in the X-API-Key header.

Manage applications

The Application tab lists every application in the organisation. Each row shows when its key was last used and when it expires, or This token has expired once it has. Click the edit icon on a row to open the application. From there you can:
  • Change the name, workspace access, or permissions, then click Update.
  • Click Regenerate key to get a new key with a new expiration. The old key stops working right away, so update it wherever it’s stored.
  • Click Delete application to remove the application and revoke its key. Any tool using the key stops working, and you can’t undo this.