Account, privacy and safety
In this section10 articles

Keep your API tokens safe

An API token acts as you in your Music24 workspace. Store it like a password and revoke it in Settings, API, the moment it leaks.

Checked on Oct 1, 2026

Treat an API token like a password. Anyone holding it can read your Music24 data, and use your account as you in that workspace, until you revoke it. It cannot change your email, create or revoke tokens, or delete your account: those need you, signed in to the app.

Store it safely

  • A token starts with m24_. We show the full token once, when you create it. We keep only a one-way hash, so we cannot show it again.
  • Keep it in a password manager, a secret manager or a server environment variable. Never put it in a public code repository, a web page or an app that others can download.
  • Give each app its own token with a clear name. Then you can revoke one without breaking the others. You can have 5 active tokens.
  • A token works in the workspace where you created it, and only there.

Revoke a token

  1. Open Settings and select API. In the apps, tap your avatar, then Settings and API.
  2. In Tokens, find the token by its name and prefix and select Revoke.
  3. Confirm with Revoke token. Every app using that token stops working right away.

When a token stops by itself

  • You leave the workspace, or its owner removes you.
  • The workspace leaves the Label plan. Requests are refused until it has API access again.
  • You delete your account. Every token is revoked.
  • Signing out does not stop a token. Revoke it in Settings, API.

AI clients (MCP)

When you approve an AI client, it gets a read-only token for your workspace: it can read your data, but every change is refused. Keep it as safe as an API token, because it reads everything in the workspace. Its access token lasts 1 hour. The client renews it by itself, and keeps access as long as it renews at least once every 30 days. To see the clients you approved, open Settings → API → Connected apps. To cut one off, select Revoke and then Revoke access: it loses access at once. If you need help, email [email protected].

Questions

I shared my API token by mistake. What do I do?

Revoke it at once in Settings, API. Then create a new token and put it in your apps. The old token stops working right away.

Can Music24 show me my token again?

No. We store only a hash of it. If you lost the token, revoke it and create a new one.

Related articles

Still stuck?

Write to us. Send the email address of your Music24 account with your question.

Email [email protected]