Skip to main content

14.8 Profile Settings and API Keys

Personal settings are available to every signed-in user. Use this dialog to maintain your profile, avatar, password, and user-level API keys. Open the avatar menu in the upper-right corner and select the top account item, which shows your avatar, email address, and name.

14.8.1 Dialog Layout

The personal settings dialog contains the following tabs:

TabPurpose
ProfileView and edit your name, email, phone number, position, and description
API KeyCreate, copy, update the expiration time of, and delete user API keys
PasskeyRegister and manage passkeys used for multi-factor authentication (MFA). See Section 14.10.
AgentConfigure personal MCP server connections based on MCP templates

14.8.2 Profile

14.8.2.1 Editable Fields

The Profile tab opens in read-only mode. Click Edit at the bottom to switch to edit mode.

FieldDescription
First Name / Last NameYour personal name
EmailSign-in email address. It is read-only here and cannot be changed from this dialog.
PhoneContact number, including country or region code
PositionOptional job title or position
DescriptionOptional personal description

Click the avatar area in the upper-left part of the dialog to upload a new avatar image. Only JPG, JPEG, and PNG files smaller than 1 MB are accepted.

14.8.2.2 Password Changes

Users who sign in with a username and password can also change their password while editing profile information. When you save, the system prompts you to re-enter your current password for confirmation. Users who sign in through OAuth 2.0 or another single sign-on method do not see the password fields.

14.8.3 API Keys

User API keys are intended for scripts, CLIs, MCP clients, and other integrations that need a stable credential. An API key uses the permission boundary of the user who created it and is sent in the Authorization: Bearer <IDMP_API_KEY> header. The copied key itself starts with api_ and does not include the Bearer prefix.

14.8.3.1 List View

The API Key tab lists keys in reverse chronological order by creation time and provides the following information and actions:

Column or ActionDescription
TitleUser-defined title. It must be unique per user.
KeyMasked API key value. Click the copy icon to retrieve the full value again.
Added onCreation date of the API key
Expired onCurrent expiration time. Click the value to open the Edit Expiration dialog.
DeleteDeletes the API key. Once confirmed, the key becomes invalid immediately.

14.8.3.2 Creating an API Key

  1. Switch to the API Key tab and click Add New API Key.
  2. Enter a unique title.
  3. Choose either Never or Expiration Date. If you specify a date, it must be later than the current time.
  4. Click Create.
  5. After creation, the system opens a dialog that shows the full API key. Copy it and store it safely.

The list view shows only a masked value. If you need the full key again later, use the row-level copy action.

14.8.3.3 Updating the Expiration Time

Click the current value in the Expired on column to open the Edit Expiration dialog. The title remains read-only in this dialog, but you can switch between Never and a new Expiration Date.

14.8.3.4 Deleting an API Key

Click the delete icon at the end of the row and confirm the action. The API key is invalidated immediately. Delete keys promptly when the associated automation or external tool is no longer needed.

14.8.3.5 Usage and Limits

  • API keys are recommended for long-running integration scenarios such as CLIs, scripts, and MCP clients.
  • The request header format is Authorization: Bearer <IDMP_API_KEY>. If a client asks only for the bearer token value, provide the raw api_... key.
  • API keys inherit the role permissions and element access scope of the user who created them.
  • An API key becomes invalid immediately when it expires, is deleted, or its owner is deactivated or deleted.
  • Requests authenticated by API key cannot access API key management endpoints. This includes listing, creating, copying, updating, and deleting keys. Manage keys from the signed-in Web UI instead.

For SDK and MCP examples that use API keys, see Section 15.1.3 and Section 15.2.

14.8.4 Passkey

The Passkey tab is where you register and manage passkeys used for multi-factor authentication (MFA). A passkey is a WebAuthn-based passwordless credential whose private key is stored in your device's keychain; verification is confirmed via fingerprint, face recognition, or your device PIN. For the complete step-up verification flow, passkey registration and deletion, and administrator-side MFA exemption configuration, see Section 14.10 Multi-Factor Authentication (MFA).

14.8.5 Agent

The Agent tab is used to configure personal MCP server connections based on MCP templates. After an administrator defines templates in Libraries → Agentic AI → MCP Templates, users fill in variable values here for each template to complete their personal MCP connection configuration.

14.8.5.1 Template List

The list displays all MCP templates created by administrators that are currently enabled, with the following information:

ColumnDescription
NameMCP template name
URL / CommandDisplays the URL for HTTP/SSE types, or the startup command for command types
StatusConnection status, depending on whether the template includes variables and whether they have been configured

Each template's status falls into one of the following categories:

StatusDescription
Auto-availableThe template defines no variables; it can be used directly without user configuration
Configuration requiredThe template defines variables, but values have not been filled in yet
ConfiguredVariables have been filled in; the connection is ready to use

14.8.5.2 Configuring Variables

For templates that include variables, click the settings icon at the end of the row to open the Variable Configuration dialog. The dialog lists all variables defined by the template along with their descriptions. Fill in each variable value and save.

To modify variable values, reopen the Variable Configuration dialog and make changes. To clear configured variable values, click the delete icon at the end of the row to restore the unconfigured state.

14.8.5.3 Sensitive Variables

If a variable is marked as sensitive, its value is always displayed in masked form in the UI. Once configured, the value of a sensitive variable cannot be viewed again and can only be overwritten by entering a new value.