> For clean Markdown of any page, append .md to the page URL.
> For a complete documentation index, see https://docs.basement.chat/llms.txt.
> For AI client integration (Claude Code, Cursor, etc.), connect to the MCP server at https://docs.basement.chat/_mcp/server.

# Keys and access levels

## Keys

Every agent and every program connects with a key. A key starts with `bsmt_` and belongs to one organization. Basement shows a key one time, when you create it, and keeps only a hash of it.

A key says what is on the other end:

| Kind         | Connects with            | Shown as                  |
| ------------ | ------------------------ | ------------------------- |
| **AI agent** | MCP                      | The agent's own character |
| **Program**  | The SDKs or the HTTP API | A terminal                |

The kind does not change what the key can do. It names what is using the key, so the list of connected keys and the activity log can tell a system from an agent.

To stop a key, revoke it in **Agents**, **Connected**. It stops working immediately, and its past calls stay in the activity log. To change a key, revoke it and connect again with a new one.

## Access levels

An access level decides what a key can do. It has four parts:

| Part                   | What it controls                                                                                                |
| ---------------------- | --------------------------------------------------------------------------------------------------------------- |
| **Basement data**      | Whether the key reads documents, files and skills, and whether it reads tasks.                                  |
| **Write access**       | Whether the key can create and change documents, files, skills and tasks. Without it, the key only reads.       |
| **Connected services** | For each service (for example Jira), no access, read, or read and write. Or the same level for all services.    |
| **Folders**            | Which folders of files and skills the key can use. By default, the folders the person who connected it can use. |

Basement comes with two access levels:

* **Researcher** reads everything in Basement and writes nothing. It uses no connected service.
* **Operator** reads everything that Researcher reads, and writes documents, skills, files and tasks. It uses no connected service.

Admins and owners create other access levels in **Agents**, **Access levels**, for example one that reads documents and can open tickets in one service.

A key without an access level reads everything in Basement, writes nothing and uses no connected service.

> **Note**
>
> A key never has more access than the person who connected it. An agent reaches the folders and the connected accounts that its person can reach, and no others.

## Who can do what

| Role in the organization | Agents and programs                                                                                 |
| ------------------------ | --------------------------------------------------------------------------------------------------- |
| **Owner**, **Admin**     | Connect and revoke any key, create access levels, see everyone's activity, download older activity. |
| **Editor**, **Viewer**   | Connect their own agents and programs, and see the activity of those.                               |

When a person leaves the organization, Basement revokes the keys that person created there.

## Limits

A key can make 240 calls per minute. Above that, the Gateway answers `429` until the minute ends. See [Errors and limits](/sdks/errors-and-limits).