How to Use Read-Only Promptwatch API Keys for Looker Studio and MCP
How we issue read-only Promptwatch API keys for Looker Studio and MCP chat, and keep write keys on the CMS-connected seat only.
Most people on an account should not be able to create prompts or push Webflow drafts. We issue read-only Promptwatch API keys for Looker Studio and for MCP chat. Write keys stay on the one seat that is connected to the CMS. That is the whole policy.
List who needs Looker, who needs MCP, and who publishes. Only the last group gets write. Essential at $95/mo includes MCP and API. That is the first brand plan where keys matter. Professional at $245/mo is where Data Studio is listed. Business is $579/mo. Kick-off is $199/mo, unlimited projects and prompts, 10 seats. Explore is free, 10 ChatGPT prompts. G2: 4.7/5.
Read-only where the key can leak
Looker: the connector takes an API key. Every analyst who can edit the report can see how the connector is set up. Use read-only. A leaked Looker key should not publish a draft. We do not put write keys in the Looker connector "so the report can add prompts." Reports do not add prompts.
MCP: Claude, Cursor, and ChatGPT store the key or the OAuth grant on a laptop. We use read-only there too. Read-only hides write tools on MCP. The chat can ask for visibility. It cannot bulk-create prompts from a year of GSC imports. Wiring: connect MCP. Confirm MCP hides write tools on the read-only key before you call the setup done.
Can we use OAuth for MCP and a key for Looker? Yes. OAuth for a named login in Claude is fine. Looker still wants a key. Both should be read-only unless that login is the CMS seat.
Project vs org: project key for one logo. Org key on Kick-off when the same Looker file or the same Cursor setup spans clients. Still read-only. We do not hand an org write key to a freelancer.
Create the read-only keys first, project or org, matching scope. Paste those into Looker and into Claude, Cursor, and ChatGPT. Slack does not get an API key pasted in the channel. Slack is a separate org-owner connection. See add the agent to Slack.
Write keys, one seat
The CMS-connected seat is the exception. Webflow OAuth and field mapping need someone who can push a draft. That person holds the write key. We still push draft, never live autopublish. Publish to Webflow. Create one write key on the CMS-connected seat. Do not copy it into Slack.
If that person leaves, we rotate the write key the same day. We do not wait for the monthly. Rotate on offboarding. Revoke laptop keys you cannot name. People stall on this because they think rotating will break Looker. It will not, if Looker is on a different key, which it should be.
What if someone needs to create prompts from Cursor? Then they are not on a read-only laptop key. We would rather they add prompts in the UI after a human cuts the list. If you insist on write-from-chat, it is a write key on a controlled machine, not in a shared repo.
We do not put write keys in GTM. Visitor analytics is a collector. GTM setup.
What read-only still can do
Pull monitors, citations, prompts, and visibility into Looker (90-day window on the connector). Ask MCP about imported GSC topics. Read persona rows. Enough for the weekly.
What it cannot do: accept a Content Agent slot, publish to Webflow, or silently grow the prompt list. Those stay human and stay on the write seat. Looker can still sit next to Google's generative AI performance reports in the same file. The key type does not change that. The GSC chart uses Google's connector.
No instant alerts either way. Keys do not change that.
FAQ
Can we use OAuth for MCP and a key for Looker?
Yes. OAuth for a named login in Claude is fine. Looker still wants a key. Both should be read-only unless that login is the CMS seat.
What if someone needs to create prompts from Cursor?
Then they are not on a read-only laptop key. We would rather they add prompts in the UI after a human cuts the list.
Does rotating the write key break Looker?
No, if Looker is on a different key, which it should be. Rotate the write key the day that person leaves. Do not wait for the monthly.
If you want the key split done, hello@1001seomedia.com. Say who edits Looker and who touches Webflow.