alc_...) from Settings → API keys. Your first key is created automatically during onboarding.
Creating a key
Each key has a label (name the tool it’s for; it helps when cleaning up later) and optional restrictions:- Read-only: the server refuses every write tool for this key. The AI can analyze and report but never change anything, see the safety model.
- Toolsets: expose only selected tool groups, which shrinks the tool list your AI loads into context. See Toolsets.
- Client scoping (agency plan): limit a key to specific clients. See Clients.
ga4-only key scoped to one client is a perfectly good reporting handout.