Access
Who can use the API
The API and the MCP server are part of a Keystone Enterprise subscription. What that includes, who it covers, and how to get access.
Everything on this site is documented in full, and all of it is available to one group: businesses on a Keystone Enterprise subscription. The Starter, Growth, and Scale plans on keystone.app include the console and the Keystone-built website; they do not include credentials for the API or the MCP server.
What Enterprise access includes
| Public API | A site API key per business, for a headless front end or any system that reads the business's published data. |
| Edits API | Reviewed changes to a business's information from your own software, with every applied change in the console's Change History. |
| MCP server | MCP access for named users, so an assistant of their choice can read the business and propose changes they review. |
| Developer support | developers@keystone.app, including the registration of OAuth redirect URIs for MCP clients Keystone has not seen before. |
| Notice of change | Breaking changes announced in the changelog before they ship, per the licence. |
The Console API and the service, provider, and auth surfaces are documented for completeness. They are the platform's own contracts, called by Keystone's software with Keystone's credentials, and are not offered to subscribers.
Who it covers
Access is granted to a business, and credentials are issued per business and per person:
- A site API key belongs to one business and reads only that business.
- A console token belongs to one person and reaches the businesses that person may edit in the console.
- MCP access is granted to one Keystone user at a time. Each user signs in to Keystone from their own MCP client; there is no shared account.
Agencies and partners managing several businesses on Keystone hold the same credentials, scoped to the businesses they manage. Nothing here grants access to a business the caller could not already open in the console.
Getting set up
- Confirm the business is on Enterprise, or arrange the move with Keystone.
- Tell developer support what you are building and which surfaces you need. For the Public API they issue the site key; for the Edits API your console sign-in already works; for MCP they grant access to the users you name.
- If you are connecting an MCP client Keystone has not registered, send its OAuth callback URI. Claude's and Cursor's are already registered; Connecting an MCP client has the details.
- Read the API licence. Using a credential is accepting it.