> ## Documentation Index
> Fetch the complete documentation index at: https://docs.makelocalads.com/llms.txt
> Use this file to discover all available pages before exploring further.

# API keys and permissions

> What each key can do, how keys expire, and what a key's monthly credit budget covers.

Every key belongs to one organization and carries one access level. What a key
can do is fixed when it is created; create a new key to change it.

## Create a key

Workspace owners and admins on the Pro or Enterprise plan create keys in
LocalAds under **Settings > API keys**. Each key has:

* a name
* an access level (see below)
* an optional expiry: 30, 90, or 365 days
* an optional monthly credit budget (see below)

The workspace owner is emailed whenever a key is created or revoked. Give every
integration or agent its own key so you can revoke it on its own.

An expired key receives `401 Unauthorized`, the same as a missing or revoked
one. Keys without an expiry do not expire.

## Access levels

Each key is created with one access level:

| Access | Can do |
| - | - |
| Full access | Everything below, including deleting products |
| Generate | Upload images, create and update products and audiences, and create campaigns, photoshoots, videos, ChatGPT ads and Amazon listing images. Cannot delete. |
| Read only | Read products, audiences, creatives, campaigns, photoshoots, videos, ChatGPT ads and Amazon listings. Never spends credits. |

## Permissions

Endpoints check these permissions:

| Operation | Permission |
| - | - |
| Retrieve the account and pricing | Any valid key |
| Upload an image | `images:upload` |
| List brands, list or retrieve products, creatives, and audiences | `products:read` |
| Create a brand or product | `products:create` |
| Update a product; add, edit or generate audiences | `products:update` |
| Delete a product or archive an audience | `products:delete` |
| List or retrieve campaigns and recipes | `campaigns:read` |
| Create a campaign, add creatives, suggest angles | `campaigns:generate` |
| List or retrieve photoshoots, templates and moodboards | `photoshoots:read` |
| Create a photoshoot, template or moodboard | `photoshoots:generate` |
| List video recipes, concepts, voices and videos | `videos:read` |
| Generate video concepts or create a video | `videos:generate` |
| List or retrieve ChatGPT ad groups | `chatgpt_ads:read` |
| Create ads, rewrite copy or targeting | `chatgpt_ads:generate` |
| Rename a ChatGPT ad group | `chatgpt_ads:update` |
| List marketplaces and listing ideas | `amazon_listings:read` |
| Write listing ideas or render listing images | `amazon_listings:generate` |
| Edit a listing idea's direction | `amazon_listings:update` |

Every `generate` permission includes the matching `read` permission, so a key
that starts work can always check on it.

<Note>
  Keys created before September 25, 2026 do not include the `videos`,
  `chatgpt_ads` or `amazon_listings` permissions, and Settings shows them as
  custom access. Create a new key to use those endpoints.
</Note>

A valid key without the required permission receives `403 Forbidden`. A
missing, disabled, expired, or invalid key receives `401 Unauthorized`.

## Monthly credit budgets

A key can carry an optional monthly credit budget. Once the credits spent by
jobs the key started this calendar month (UTC) reach the budget, requests that
start new generation return `422` with the code `key_budget_exceeded`. Reads
keep working. The check runs before a job starts, so a single job can finish
slightly over the budget.

See [Credits and spending](/concepts/credits-and-spending) for the rest of the
spending model.
