A key is how a server knows a request is yours. Anyone holding it can make requests as you, against your allowance and your subscription. Looking after it is mostly a matter of knowing the places it should never be. Working with an agent adds a few.

Where it does go

NoVo’s key is sent in a request header. Either as Authorization: Bearer followed by the key, or in the header x-novo-api-key. That is the whole list. In an AI app, the header is set once in the place the client keeps a connector’s credentials. The model does not need to see it.

Many of the tools need no key at all. A free key raises the request ceiling and opens no extra data. So there is no reason to hand a key around to make something work.

Not in a URL

A key in a query string is never read by NoVo’s server. This is deliberate. A URL gets written to logs, saved in browser history and used in cache keys. A key placed there is copied to places you do not control. If you find yourself adding the key to the end of an address, stop. It will not work, and it has already been recorded somewhere.

Not in the conversation

Do not paste a key into a chat with an agent. The text of a conversation may be stored, and it is fed back to the model on every turn. A model that has seen the key can repeat it in an answer, in a file it writes, or in a call to a different server. Give the agent access to the connector and keep the key out of the transcript.

For the same reason, do not put a key in the agent’s standing instructions. Those are text too.

Not in anything you share

If you write a small script, keep the key out of the script itself. Code gets shared, pasted into forums for help and pushed to public repositories. Read the key from somewhere private at run time. The same goes for notebooks and spreadsheets that leave your machine.

When something breaks, people post a picture of the error. If the picture shows a settings panel or a request with its headers, the key is in it. Check before sharing. This is the most common leak, and it is entirely avoidable.

Not with another service

A key issued by one server should only ever be sent to that server. An agent connected to several servers must not pass credentials between them. If a tool or a web page asks the agent for your key, the answer is no. That limit sits with the others in what a market agent should never be allowed to do.

The key says who is asking. What opens for you depends on the subscription behind it. Those are separate things, set out in your API key says who you are, not what you bought. A leaked key is still a problem on a free plan, because someone else can use up your allowance.

If it has leaked

Assume it is in use. Stop sending it, and contact NoVo to have it retired and replaced. Then find the place it leaked from and remove it there. Do not wait to see whether anyone uses it.

How one key covers both of NoVo’s books is in one key should open everything you bought. The header formats are documented on the MCP & API page.