Which key do I use?
The four kinds of key and sign-in in Amino Engine, what each one can do, where to make it, and how to cut it off.
Where it is in the app
Open Home, choose Settings, then General › API keys.
- Home
- Settings
- General
- API keys
Amino Engine has a few different keys. They look alike and do different things. A key is another way into your account, so give each one the least it needs.
#At a glance
| Kind | Starts with | Made at | What it can do |
|---|---|---|---|
| Server key | ae_live_ |
Settings → General → API keys | Send events, contacts, consent, catalog and email from your server. Needs signed requests. |
| Public key | ae_pub_ |
Settings → General → API keys, under Browser tracking | Report page views and browsing from a visitor's browser. Nothing else. |
| Agent key | ae_agent_ |
Agents & API | Let an AI read and build flows, emails, lists and ad links. |
| Ads address | none | Advertising → Connections | Let your AI read your ad accounts. You sign in with your Amino Engine login. |
Only owners and admins can create, replace or revoke keys.
#Server key
Starts with ae_live_. This is the key for your own store code, your receipts, and your login codes.
Go to Settings → General → API keys.
On screenSettings › General › API keysPress Create key.
Give it a name, such as "Store", and pick when it expires.
Press Create and copy the key.
It is shown once. We keep only a fingerprint. If you lose it, make a new one.
- Keep it on your server. Never put it in a web page, an app, or anything a browser downloads.
- Every request with it has to be signed. See "Connect a custom-built store with the API".
- Use a separate key for staging. A key can be tied to one site address, and a request from another site is refused.
- To stop a key, revoke it on the same page.
#Public key
Starts with ae_pub_. It goes in the page source, so it is not a secret. It can only report browsing, such as page views, product views and carts. It cannot name a person by email, record consent, or create contacts.
Make it under Browser tracking on the API keys page: type your site's address, press Create browser key, and copy the tag into the <head> of every page.
#Agent key
Starts with ae_agent_. This is the key you give to Claude Code, claude.ai or another AI so it can build flows.
- Make it on the Agents & API screen with Issue key. The old address
/settings/agentsopens API keys. - There is one per brand. A new key stops the old one at once.
- It is shown once.
- Agent on / off switches every request off without losing the key. Build drafts only and May switch flows on decide how much it can do.
See "Agents and the API".
#The ads address and its key for scripts
Your ad accounts use a different door. On Advertising → Connections, the MCP server line shows an address. Paste it into Claude, ChatGPT or Claude Code, sign in with your Amino Engine login, and press Allow. No key is needed.
Cursor and your own scripts cannot use the sign-in window, so they use a key instead:
On Connections, under the address, open Advanced: scripts. Owners and admins only.
Press Reveal or the copy icon to see the key.
Send it as an
Authorization: Bearerheader, or put it on the end of the address as?token=followed by the key.If it leaks, press Make a new key. "A new key stops the old one at once. Anything using it must get the new one."
Treat it like a password.
#If it didn't work
- 401 on the server API. The key is wrong or revoked, or the signature or clock is off. See "Connect a custom-built store with the API".
- 403 when sending email. You used a public key. Only a server key can send mail.
- The agent says its key is wrong. Issue a new one on Agents & API.
- You cannot see any key screen. Your role is not owner or admin.
- A key was exposed. Revoke or replace it now. A server key and an agent key stop working at once.