API Keys
Create team API keys in Administration, restrict them with scopes, reroll, and delete them.
API Keys
With API keys, you can authenticate integrations against the TeamPanel API — without logging in to the web app.
Where to find the page
Administration → API Keys
Superadmin only
API keys can only be managed by team members with the Superadmin permission.
Create a key
- Open Administration → API Keys.
- Click Create new API key.
- Optionally enter a description (e.g. "Zapier" or "AI bot").
- Optionally select a team member as context.
- Optionally select scopes to restrict the key (see Scopes).
- Confirm with Create and copy the displayed key immediately.
Member context
- With member: The API acts with that member's permissions (modules, ToDo boards, etc.).
- Without member: The team owner context applies.
If scopes are set, the key may only do what both the member and the scopes allow.
Shown only once
The full key is only displayed when it is created (or after rerolling). After that, you can no longer see it.
Scopes
When creating a key, you can restrict it to specific scopes. This way a game server, for example, only gets upload access to media, even if the linked member may do more.
- No scopes selected: full access – existing keys keep working unchanged.
- Format:
area:readorarea:write–writeincludesread. - In addition, the permissions of the linked member (or the owner) always apply. A scope never grants permissions, it only restricts them.
- Scopes can be edited later on the API Keys page – without regenerating the key.
| Area | Covers |
|---|---|
team | Team, members, groups, permissions |
news | Announcements |
links | Links |
access | Access documentation |
logoff | Log-offs |
meetings | Meetings |
penaltypoints | Penalty points |
worrybox | Worry box |
webportal | Application portal (portal pages and settings) |
applications | Applications |
automation | Automations |
discord | Discord bot |
support | Support cases |
todo | To-do boards and tasks |
documents | Documents |
media | Media |
Special scopes:
| Scope | Meaning |
|---|---|
media:upload | Only the two upload routes of the Media API – no reading or deleting |
gameserver | GamePanel server API (connection of your game server) |
mcp | MCP endpoint. The tools it calls additionally need their area scopes |
Recommendation for game servers
Give every game server its own key with only media:upload. If the key leaks, it can only be
used to upload – and you can reroll or delete it individually.
Reroll
Via Reroll, you generate a new key. The previous one becomes invalid immediately — update all integrations that use the old key.
Delete
You should delete keys you no longer need. This action cannot be undone.
MCP / AI clients
You can use the same key in AI clients (e.g. Cursor) as a Remote MCP connection. Endpoint, tools, and a Cursor example are documented under MCP.
Use the API
How to use the key in requests, which endpoints are available, and what remains blocked is documented under API & Developers.
Templates require a signed-in session and are not available through API keys. Legacy templates:read/templates:write values grant no access; they are not automatically converted to full access.