Create a separate API key for each integration so you can choose the events and actions it can access. API and MCP access require an active paid HeySummit plan. A key never grants more access than the HeySummit user who owns it.
Create a key
Open API keys in your account dashboard. You can also follow Manage API keys from your event's API, MCP & Webhooks settings.
Choose Create an API key and give it a name that identifies the integration.
Choose Selected events and select the events it needs, or choose All current and future events I can access.
Enable only the permissions the integration needs. Read, create/update, attendee sign-in links and deletion are separate permissions.
Choose Create key, then copy the secret into a secure password manager and your integration. A new key secret is shown only once.
Choose event access and permissions
Selected-event keys can work only with the events you choose. All-event keys include current and future events you can access. Your existing event role and permissions still apply, so selecting an event does not give you access to data or actions your account cannot use.
A reporting integration usually needs read permissions for the data it reports on.
An integration that changes records also needs the relevant create/update permission.
To create new events, choose All current and future events I can access and enable Create and update event basics.
Enable temporary attendee sign-in links or deletion only when your integration needs them.
Connect an integration
For API v2 event endpoints or MCP clients that accept custom headers, send Authorization: Token YOUR_API_KEY. Replace YOUR_API_KEY with your secret. Keep it private and never include it in a public URL or screenshot.
Keep existing integrations working
Restricted keys support API v2 event endpoints and MCP only. Legacy API integrations, Zapier and account-wide webhook endpoints need your existing unrestricted token. Create a separate key for a new integration to keep those connections working. If you edit restrictions on an existing token, every integration using that token is affected.
Edit, rotate or delete a key
Edit access: change the key's events or permissions when an integration's needs change. The new restrictions affect all integrations using that key.
Rotate: replace the secret. The old secret stops working immediately, so update every integration using it. Copy the new secret when it is shown; it is shown only once.
Delete: stop access through that key. Integrations using it will fail until you connect them with another valid key.
Restore a revoked key: rotating it restores its configured access with a new secret. Reconnect the integration using that new secret.
If an event or action is unavailable
Check that your account has an active paid plan and can access the event.
For a selected-event key, check that the event is included.
Check both the key permission and your own event permissions for the requested action.
If a legacy integration fails after restrictions were added, use its existing unrestricted token or create a separate key for API v2/MCP.
If you lost a newly created secret, rotate the key and save the replacement securely.
Connect an AI assistant
OAuth connections also ask you to choose event access when you approve a new connection. Existing OAuth grants keep their previous access. See Connect an AI Assistant to HeySummit with MCP for setup and approval guidance.

