Skip to content

Credentials

API credentials let your code and agents use SignalSitter. Manage them in Settings > API credentials. A credential belongs to the project that’s selected when you issue it.

  1. Enter a Credential label, so you know what uses it.
  2. Choose a Scope preset (below).
  3. Optional: set Expires (optional). Leave it blank for no expiry.
  4. Press Issue credential.
  5. Press Copy the API credential and store it in your secret manager. It’s shown once.
  6. Tick the box confirming you’ve stored it, then press Acknowledge and hide this secret.

The one-time API credential panel for a new deploy-pipeline credential showing an example secret, a Copy the API credential button, the acknowledgement checkbox and Acknowledge and hide this secret, above the Issue an API credential and Connect remote MCP cards

Pick the smallest preset that covers the job.

Preset Can
Read Read monitors, incidents, callbacks, observations and usage. Can’t publish or change anything.
Write Publish beats to monitors that already exist. Reads nothing.
Read and write Read everything and publish beats. Can’t create, edit, pause or delete a monitor.
Manage Everything above, plus create or change monitors, projects, incidents, callbacks and credentials.

Creating a monitor gives you its own publish credential, so you don’t need one here for a single job.

Organization credentials shows each credential’s Public prefix, Created, Last used, Expires and Granted scopes. The full secret never appears again.

  1. Press Rotate, then Rotate this credential.
  2. Copy the new secret. It’s shown once.
  3. Update your clients. The old secret keeps working for a short overlap.

Press Revoke, then Revoke this credential. It stops working at once.

Use Connect remote MCP to set up an MCP client without pasting the secret into a file.

  1. Copy the Remote Streamable HTTP endpoint with the copy button beside it.
  2. Under Credential whose grants you are configuring, choose an active credential.
  3. Pick a Named client: Codex, Claude Code or VS Code.
  4. Copy the Environment-backed configuration with its copy button and add it to your client.
  5. Set SIGNALSITTER_API_KEY to the credential in the client’s private environment or secret prompt. The copied configuration contains no secret.

The Connect remote MCP card with the remote MCP endpoint, the ops-agent Manage credential selected with its granted scopes, Claude Code chosen as the named client, and its environment-backed configuration

See MCP for what an agent can do once connected.