API tokens and audit logs
Create tokens for the OpsLyft API and MCP servers, and review who did what.
API access tokens
Settings → API Access Tokens is where you create and rotate tokens for:
- the OpsLyft API;
- MCP servers that FinOps Copilot connects to.
When a token expires, the feature that uses it stops and OpsLyft adds an item to Needs attention with a Rotate button.
Audit logs
Settings → Audit Logs records who did what, and when, across the workspace: sign-ins, setting changes, connection changes, and actions on findings.
The API Access Tokens and Audit Logs pages are rolling out in v2.