Connect with a key
Create a long-lived key for Claude Code, Cursor or a script, and add it to a client that can't open a browser.
Settings → Developers → Connect an assistant → Another tool or a script (or Use a key instead under Claude Code and Cursor). Name it, tick the permissions, copy the key — it is shown once — and paste what the dialog gives you where the key will run.
A key is the alternative to signing in through a browser. Everything else is identical: the same permissions, the same limits, the same row in the connections list.
Use the browser sign-in of Claude, Claude Code or Cursor instead when a browser is available. It is fewer steps and leaves no secret in a shell history.
When a key is the right answer
- A machine with no browser — a server, a container, a CI job.
- A script that calls LeadMove on a schedule and has nobody to click Approve.
- A client that doesn't do OAuth but can send an
Authorizationheader.
Creating one
The dialog asks for two things.
Name. The machine that will hold it — "Claude Code on my laptop", "Reporting box". You read this name in the connections list, in the revoke dialog and in the activity log months later, so name the holder, not the intent. Up to 60 characters, and no two live connections may share one.
Permissions. Read is ticked by default. Anything above your role is greyed out with the role it needs. They cannot be widened afterwards — a different set of rights is a different connection, created on purpose.
The key is lm_mcp_ followed by 43 random characters. We store only its fingerprint, so nobody, including us, can show it to you again. The dialog won't let you close it until you have copied it.
What the dialog gives you next depends on where you said the key would run: the command for Claude Code, the JSON block for Cursor, or, for another tool, the server URL and the two headers, each with its own Copy button.
Not ready to plug it in? Just create a key for now, under the tiles, makes a named key without choosing a client.
Setup guide
A key that has not made a single call yet shows Not used yet on its row, with a Setup guide button. The guide reopens the last step of the path the key was made for, the command, the JSON or the lines to paste, so you can finish the setup later. The key itself is never shown again: the guide shows it masked. Lost it before using it? Revoke the connection and create a new one.
Once the key has made its first call, the badge and the button go away.
Adding it to Claude Code
The dialog hands you the whole command, key included:
Then /mcp in Claude Code lists the tools. No sign-in step: the key is the sign-in.
Adding it to Cursor
The dialog hands you the block for ~/.cursor/mcp.json, key included:
Restart Cursor. More clients in other MCP clients.
Keeping a key safe
- Store it in a secret manager or an environment variable. Never in a repository, a spreadsheet, a ticket or a URL.
- Never in anything that runs in a browser or a mobile app — a key in client-side code is a public key.
- One key per machine. Then revoking the one that leaked doesn't take the others down.
- Last used in the connections list tells you whether a key is still in service before you revoke it. It updates at most once a minute.
A key is not a public API key and the two are not interchangeable: an lm_live_ key from the API keys section is rejected here, and an lm_mcp_ key is rejected there.
Rotating one
There is no rotate button, deliberately. Create a replacement, roll it out, then revoke the old one — that way there is never a window where the machine is down, and the handover is two dated events rather than a silent swap.
Calling it from a script
A key also works without any MCP client, from a plain HTTP script:
- URL:
https://app.leadmove.io/mcp,POST, a JSON-RPC body (tools/list, thentools/call). - Headers:
Authorization: Bearer lm_mcp_…,Content-Type: application/jsonandAccept: application/json, text/event-stream. Without thatAcceptheader the server refuses the request. - No session: the server keeps no state between requests, so each call stands on its own. There is no session id to carry and nothing to close.
A tool your account switched off in Settings → Developers → Assistant access answers writes_disabled, with the switch to turn back on.
Options on a key
Open the connection by clicking its name in Settings → Developers to reach them.
Mask personal fields. Names, emails and phone numbers leave the account partly hidden. On for members always, off by default for admins and owners.
Auto-confirm low-risk changes. Owner-only, key connections only. Pause, resume, closing dates, rule toggles, disabling an endpoint and choosing a buyer's default one would apply without a preview; everything else still asks — including any change to a buyer's own settings, such as its tags — and so does switching a delivery endpoint on. It only matters on a key that holds a write permission.
Limits. 120 requests a minute, and a daily budget on changes. They are shown, not editable: you can ask us to lower one, and we raise one on request.
Suspending
Suspend in the connection's menu stops it at once without deleting it; Resume brings it back with the same key. Use it when you are not sure yet: a key you only suspended can be trusted again, a revoked one cannot.
Revoking
Open the connection and Revoke. It takes effect on the very next request, including one already in flight. Revoked connections move behind Show revoked below the list, so the activity log can still name what acted.