Settings and developer access

What each Settings page holds, and how to create, replace and revoke API keys and authorized apps.

Settings holds each workspace's configuration and your own profile. Its Developer page is where you create, replace and revoke API keys, and revoke apps you authorized.

Open Settings from the account menu at the bottom of the sidebar, or press G then S.

Settings pages

Settings shows the active workspace. To change another one, switch to it from the account menu first.

  • General: the workspace's name. Admins can change it.
  • Members: the organization's members, their roles and Pending invites. Personal workspaces don't have this page. See Organizations and members.
  • Integrations: opens the GitHub page, where you install the V12 GitHub App and add public repositories. See Connect GitHub.
  • Billing: Credit, Usage and Spending limits. See Credits and billing.
  • Developer: API keys and authorized apps, described below.
  • Profile: your own account, the same in every workspace: your Username, your email, and Connected accounts, where you Connect or Disconnect GitHub.

Settings opens on General. In an organization, Profile is listed under Account. A personal workspace has no separate Profile: its General page holds your profile, and your Username is also the workspace's name.

Username

V12 names you to your teammates by your username: on findings you own, in Activity, in assignment menus and filters, and in the member list. It starts as your GitHub login when you sign up with GitHub, and as the part of your email before the @ otherwise; change it under Profile.

  • A username is 3 to 39 lowercase letters, digits and single hyphens, with at least one letter.
  • Usernames don't have to be unique. Where two people in a workspace have names that read alike, their teammates see each one's email beside it.
  • Names that could pass for V12 or for a system label, such as v12, admin or unassigned, are reserved.
  • A guest reading a repository shared with them sees members by username only, and is marked guest in the organization's Activity.

API keys

An API key lets a script, a CI job or another tool call the V12 API as you.

  • A key belongs to the workspace that is active when you create it, personal or organization, and works only there. To make a key for another workspace, switch to it first. See Which organization a token reads.
  • Admins and Members can both create keys. Each person can have up to 50 active keys in a workspace.
  • The API keys table has the columns Key (the name), Prefix, Scopes and Last used.
  • In an organization, Admins see every member's keys, with a Created by column. Members see only their own.

Create an API key

Go to Settings → Developer and click Create key.

In the Create a key dialog, enter a name for the key in the first field, for example "CI gate".

Select at least one scope. Each option shows a label, such as View findings, above its scope, such as findings:read. Create stays disabled until the key has a name and a scope. For what each scope allows, see Scopes.

Click Create. The dialog shows the key and says "This secret is shown once. Copy it now." Copy the key into your secret store, then click Done.

Keys start with v12p_. A key created here has no expiry date. It works until someone revokes it, until its creator stops being a member of the workspace, or until its creator changes or resets their password, which revokes all of that person's keys.

Rename or revoke

Each key's row has a menu at its right end with Rename and Revoke.

  • Rename turns the name into a field. Press Enter to save or Escape to cancel. Only the key's creator can rename it.
  • Revoke takes effect at once: the next request that uses the key gets a 401. Admins can revoke any key in their organization.

You can't change a key's scopes. To give a tool different scopes, replace its key.

Replace a key

V12 can't rotate a key in place. To swap one without an outage:

  1. Create a new key with the scopes you need.
  2. Update the secret wherever the old key is stored.
  3. Check the new key:
    curl -s -H "Authorization: Bearer $NEW_KEY" https://v12.sh/api/v2/me
    The response names the workspace and lists the key's scopes. This call needs View account and members: a 403 means the key works but lacks that scope, and a 401 means the key is wrong.
  4. Revoke the old key.

Authorized apps

Apps you connect to V12 over OAuth, such as an MCP client or the V12 CLI, appear under Authorized apps on the Developer page. The section appears only when there is an app to list.

  • The columns are App, Scopes and Last used.
  • In an organization, Admins see every member's apps, with an Authorized by column. Members see only their own.
  • Revoke disconnects an app at once, without asking for confirmation. As the page says, "Revoking an app invalidates its tokens immediately." To use the app again, authorize it again.

On this page