Security
- Treat the MCP key like a password. Rotate it immediately if it is shared, logged, or committed to
source control.
- Prefer environment variables over pasting the key into shared or version-controlled config files.
- Use least privilege — create separate MCP servers and keys per environment (dev/staging/prod) and
per integration.
Related Docs
- Deploy an assistant — embed the same assistant on a website.
- Build a perfect assistant — create and tune the assistants you expose over MCP.
- Admin & billing — MCP servers appear as billable artifacts in usage.