TeamPanel
Team Management

API Keys

Create team API keys in Administration, restrict them with scopes, reroll, and delete them.

API Keys

With API keys, you can authenticate integrations against the TeamPanel API — without logging in to the web app.

Where to find the page

Administration → API Keys

Superadmin only

API keys can only be managed by team members with the Superadmin permission.

Create a key

  1. Open Administration → API Keys.
  2. Click Create new API key.
  3. Optionally enter a description (e.g. "Zapier" or "AI bot").
  4. Optionally select a team member as context.
  5. Optionally select scopes to restrict the key (see Scopes).
  6. Confirm with Create and copy the displayed key immediately.

Member context

  • With member: The API acts with that member's permissions (modules, ToDo boards, etc.).
  • Without member: The team owner context applies.

If scopes are set, the key may only do what both the member and the scopes allow.

Shown only once

The full key is only displayed when it is created (or after rerolling). After that, you can no longer see it.

Scopes

When creating a key, you can restrict it to specific scopes. This way a game server, for example, only gets upload access to media, even if the linked member may do more.

  • No scopes selected: full access – existing keys keep working unchanged.
  • Format: area:read or area:write – write includes read.
  • In addition, the permissions of the linked member (or the owner) always apply. A scope never grants permissions, it only restricts them.
  • Scopes can be edited later on the API Keys page – without regenerating the key.
AreaCovers
teamTeam, members, groups, permissions
newsAnnouncements
linksLinks
accessAccess documentation
logoffLog-offs
meetingsMeetings
penaltypointsPenalty points
worryboxWorry box
webportalApplication portal (portal pages and settings)
applicationsApplications
automationAutomations
discordDiscord bot
supportSupport cases
todoTo-do boards and tasks
documentsDocuments
mediaMedia

Special scopes:

ScopeMeaning
media:uploadOnly the two upload routes of the Media API – no reading or deleting
gameserverGamePanel server API (connection of your game server)
mcpMCP endpoint. The tools it calls additionally need their area scopes

Recommendation for game servers

Give every game server its own key with only media:upload. If the key leaks, it can only be used to upload – and you can reroll or delete it individually.

Reroll

Via Reroll, you generate a new key. The previous one becomes invalid immediately — update all integrations that use the old key.

Delete

You should delete keys you no longer need. This action cannot be undone.

MCP / AI clients

You can use the same key in AI clients (e.g. Cursor) as a Remote MCP connection. Endpoint, tools, and a Cursor example are documented under MCP.

Use the API

How to use the key in requests, which endpoints are available, and what remains blocked is documented under API & Developers.

Templates require a signed-in session and are not available through API keys. Legacy templates:read/templates:write values grant no access; they are not automatically converted to full access.

On this page