Create a key
For a personal key, open Account Settings → API Keys. For a team key, an administrator opens Team Settings → Team API Keys. Choose Create API key, then enter a Name, choose Permissions, and choose Expires after. All three are required. You may be asked to confirm your identity before the key is issued.
Choose 30 days, 90 days or 1 year for expiry. Only an administrator can choose Never. A key’s grant cannot exceed its issuer’s authority at creation. A personal key also remains bounded by its owner’s current active membership and role. If that owner is demoted, the stored grant narrows permanently, even if the owner is promoted later. A team key uses its stored team grant independently of its creator’s later membership.
The Copy your API key dialog shows the complete token once. Copy it into the client’s secret store before closing the dialog. Mill stores a hash; the key list later shows metadata such as name, expiry and last use, but cannot reveal the token again. Never put it in a repository, task comment, prompt or screenshot.
Use and revoke a key
Send the token as a bearer credential to REST or/mcp. For example, after loading it into MILL_TOKEN from your secret store:
Idempotency-Key for each intended REST mutation and reuse that same key when retrying an uncertain request. Task edits and deletes also need the current task version. See REST and MCP clients for a complete connection example and the REST API for fields and errors.
Use the key’s Revoke action when the integration no longer needs access. Revocation ends access on the next request and removes the key from the active list. Expired keys remain listed until revoked. Password changes and account recovery revoke personal keys owned by that person. Team keys remain subject to their stored team policy, so administrators should review them separately when membership changes.
An Administrative personal key can delete a board only while its owner remains an active Admin with that stored grant. An Administrative team key uses its stored team policy even if its creator later leaves or is disabled. Neither key type can manage accounts, invitations, membership, sessions, credentials, or OAuth consent; those actions require a browser session. OAuth connections cannot delete boards. For a client connection tied to a person’s approved scopes and boards, use MCP OAuth.
In the app
Personal API keys
- Desktop
- Mobile
Team API keys
- Desktop
- Mobile
