Skip to content

API Access

Admin > Settings > API Access (/admin/settings/api) is where you let software act on the club’s behalf: the klahaya command-line tool for bulk loads, or an AI agent connected through the portal’s MCP endpoint. Everything created here is visible to every admin, and everything it changes is recorded with a way to undo it.

The Admin API card has one switch, Enable the admin API. Turning it off makes every API, MCP and token request answer “unavailable” within 30 seconds — a kill switch. Existing tokens are not revoked; turn it back on and they work again.

Every credential has one or two scopes:

  • Read — every family, roster, lesson, volunteer and hours record. Always included.
  • Write — create and update lesson programs, sessions, classes, class prices and registration windows; volunteer events, shifts and signups; log volunteer hours; and edit member and family member details. Never deletes, moves money, or changes settings.

Writes are never applied directly. A write operation produces a plan — the rows it would create or change and the emails it would send — and only a separate apply step performs it. Every apply is recorded under Changes made through the API with a per-record before/after and an Undo button. See API Changes and Undo.

Personal access tokens are for the command line. Applications and agents connect through the consent screen instead (below) and appear in the list automatically.

  1. Under Create a personal access token, give it a Name you will recognize in the list (for example, “laptop cli”).

  2. Under Access, tick Write if the token needs to change anything. Read is always included.

  3. Choose Expires after — 30, 90, 180 or 365 days — and click Create token.

  4. Copy this token now. It is shown once. Use Copy, paste it where it is needed (for example klahaya login), then click I’ve saved it. The portal stores only a hash; if you lose the token, revoke it and make a new one.

The Connecting an agent card shows the one-line command for Claude Code, and the same endpoint works for any MCP client:

claude mcp add --transport http klahaya https://members.klahaya.net/api/mcp

The first time the agent talks to the portal, your browser opens a Connect …? screen naming the application and what it will be able to do. You must be signed in as an admin and not impersonating anyone. Review the scopes and click Approve (or Deny). Access renews itself hourly and the connection lasts up to 90 days; revoke it at any time from this page.

Tokens and connections lists every credential on the club account, whoever created it: Personal access tokens (name, the first characters of the token, scopes, owner, created, expires, last used) and Connected applications (the application’s name, scopes, owner, when it connected, last used). Each shows Active, Expired or Revoked.

Click Revoke to stop a credential. Anything using it stops working immediately, and this cannot be undone. Any admin can revoke any credential, including another admin’s.