Skip to content

Create an MCP key

Cursor, Claude, and Grok inside Cursor connect with the URL only and sign in with OAuth. They do not need a key.

An MCP key is for scheduled jobs, cron, and raw HTTP: Grok Bot and similar machines that send Accept: application/json, text/event-stream, a Chrome User-Agent, and Authorization: Bearer. It is a long secret that starts with flyga_mcp_. Treat it like a password. It can read and update your Plan account. It only works with Flyga MCP, not the website’s REST API.

If you do not see API keys under Account, MCP keys are not enabled for your account yet. You can still connect Cursor and Claude without a key.

On go.flyga.app, open Account → API keys.

Account API keys page with the MCP keys list Account API keys page with the MCP keys list

Click New key. Name it after the machine that will send it — “Grok Bot weekly optimizer”, “curl on the NAS”.

Leave the switches on Always allow for anything you want that agent to do. Turn a group to Don’t allow if this key should not see that part of your account (for example, a read-only catalog key with Wallet and Transfers off).

New MCP key dialog with name and Always allow switches New MCP key dialog with name and Always allow switches
GroupWhat the agent can do
CatalogPrograms, valuations, live bonuses, transfer options, Transfer Optimizer, airports, airlines, and reporting catalog data issues
RedemptionsList your award bookings; Write logs or edits them
TransfersList recorded transfers; Write logs or edits them
WalletSee tracked balances; Write updates a balance or starts tracking a program
BenefitsList card benefit claims; Write marks them used, hidden, or written off

Click Create.

The full key is shown once. Copy it into the agent’s secret store or the client’s config. If you close the dialog without copying, mint another key.

Copy this key now dialog with the flyga_mcp secret Copy this key now dialog with the flyga_mcp secret

Those switches are the hard limit for the key. Always allow means Flyga will run that kind of call. Don’t allow hides it so the agent cannot call it.

Claude and Cursor may still ask “allow this tool?” before they send anything. That prompt is in the assistant, not in Flyga.

You can change a key’s permissions later from the same page. Revoke it if it leaks — it stops working on the next request.

Point the machine at https://api.flyga.app/mcp (keep /mcp, no trailing slash). Send all three:

  • Authorization: Bearer plus the flyga_mcp_ secret
  • Accept: application/json, text/event-stream
  • a Chrome User-Agent

Put the secret in the job’s environment or the client’s private config.