# How to get access (https://developers.asip.io/docs/how-to-get-access)

Developer access is off for every company until ASIP enables it. Here is who does what, in order.

> **Status: Available on request.** API keys, the read-only Data API, the MCP server (with an API key) and signed webhooks are live on app.asip.io. Developer access is off by default for every company: ask ASIP to enable it for yours (https://developers.asip.io/docs/how-to-get-access). One-click OAuth sign-in for AI connectors (claude.ai, ChatGPT, Copilot) is not available yet; use an API key. The changelog at https://developers.asip.io/docs/changelog says when each part becomes available.

API keys, the read-only [Data API](/docs/api-reference), the [MCP server](/docs/mcp-reference) and
signed [webhooks](/docs/webhooks) are live on app.asip.io. They are **available on request**:
developer access is off for every company until ASIP enables it, and then your company decides who
may use it.

1. **Your company asks ASIP**

   Ask your ASIP contact to enable developer access for your company. ASIP switches it on for your
   company in its own Global Admin console.

   This is ASIP's switch, and it sits above your company's own. ASIP can switch it off again at any
   time; that is the **kill switch**. While it is off, no key in your company works, no new key can be
   created, and no webhook is sent.

2. **Your company admin turns it on and chooses who**

   A company administrator then:

   1. turns developer access on in **Admin → API keys** (the switch cannot be turned on until ASIP has
      enabled your company); and
   2. grants the **Issue and revoke API keys** privilege (manage developer access) to the people who
      should have it, in **Users & Permissions**. Nobody holds it by default, company administrators
      included: an admin who needs it grants it to themselves, where everyone can see it.

   The same admin page lists every key in the company, and holders of the privilege can revoke any of
   them.

3. **Those people create their own keys**

   Each person who holds the privilege creates their own keys in **My Account → Developer access**. A key
   belongs to the person who created it. Creating one asks for a passkey confirmation, the key is shown
   **once**, and it expires after at most one year. See [Getting started](/docs/getting-started).

   The same people can set up [webhook endpoints](/docs/webhooks) in **Admin → Webhooks**.

## A key never sees more than its person

A key reads only what its owner can see in ASIP today, checked again on every call: their role, their
stations and their company's modules. It can only read, never change anything.

A key stops working **on its next call** when any of these happens:

* the key is revoked, or it expires;
* its owner loses the **Issue and revoke API keys** privilege;
* its owner is deactivated, or their sessions are reset (for example after a password reset);
* the company admin switches developer access off;
* ASIP switches developer access off for the company.

Every refusal of a key or token is the same `401 unauthenticated`, with no hint which check failed. A
key that is accepted but lacks the scope a resource needs gets `403 insufficient_scope`. See
[Errors](/docs/errors#how-a-refused-api-key-is-answered).

## Connecting AI tools

Today, connect an AI tool with an API key: see [Connect your AI](/docs/connect-your-ai). One-click
sign-in for claude.ai, ChatGPT and Copilot connectors is coming soon — until then, use an API key.
