# LegoTechApps API Authentication and Permissions

Official LegoTechApps authentication guide for scoped API keys, MCP permissions, read-only access, write access, revocation and secret handling.

Canonical: https://app.legotechapps.com/developers/authentication/

## Create a scoped key

Sign in to LegoTechApps, open AI connections, choose the business and permitted modules, keep the key read-only unless writes are necessary, and create the key. The full secret is shown only when created.

```text
Dashboard → AI connections → New connection
```

## Send and store it safely

Send the key as an Authorization bearer token to the authenticated MCP endpoint. Store it in a secret manager or environment variable; never place it in client-side code, URLs, public prompts or source control.

```text
Authorization: Bearer <scoped-key>
```

## Revoke and rotate

Revoke a connection from the dashboard when a device, agent or teammate no longer needs it. Reconnection does not silently restart bots, replay actions or expand permissions.

```text
Authenticated endpoint: https://legotechapps.com/lt/api/mcp
```

## Resources

- [MCP guide](https://app.legotechapps.com/developers/mcp/)
- [API guide](https://app.legotechapps.com/developers/api/)
- [Privacy](https://legotechapps.com/privacy)
- [Developer support](https://legotechapps.com/contact/)
