MCP access uses a personal API key — each team member can have one active key, managed under Settings → MCP API Access. Keys start with sc_mcp_live_.
Generating a key
- 1Go to Settings and find the MCP API Access section on the Account tab
- 2Tick the permissions the key should have — the read-only permissions are pre-selected as sensible defaults
- 3If you select Create labels, confirm the acknowledgement: "I understand that connected MCP clients will be able to create shipping labels on my behalf."
- 4Click Generate API key
- 5Copy the key immediately — for security reasons, it will not be shown again
Permissions (scopes)
A key only grants what you select. Available permissions include reading your account profile, statistics, shipments, labels, sender addresses, and package presets; creating shipment drafts; writing customs declarations; reading billing usage; and — marked as Sensitive — creating labels. Label creation is off by default and requires the explicit acknowledgement above, because connected clients can then make purchases that count against your plan.
Permissions follow your role
A key can never do more than you can. You can only assign permissions that are currently available to your ShipCelero user — for example, billing access is only available where you can see Billing. On every request, the effective permissions are recalculated as the key's permissions intersected with your current permissions:
- If your permissions are reduced (role change, billing hidden), the affected key permissions stop working immediately — no key change needed. They show as Inactive on the settings page.
- If your user or account is suspended, the key stops working entirely.
Changing permissions
- Removing a permission applies immediately to connected clients — no new key needed
- Adding a permission requires regenerating the key (Regenerate with new permissions)
Regenerate and revoke
Regenerate key issues a replacement and immediately disables the old key — update every connected client with the new key. Revoke key disables the key immediately without a replacement; all connected clients lose access at once. The settings page shows the key prefix, creation date, and when it was last used, so you can tell whether it is still in use.