Team members and roles
You invite teammates by email from the desk, and each member has a role that controls what they can do:
Every role can read the account (markets, balance, positions) so the desk renders for everyone; roles differ only in what a member can change.
API keys
API keys are created and revoked by admins on the desk. The full key is shown only once at creation, so store it securely. The API is authenticated by the key itself, independently of who is logged into the desk - see Authentication. Usemk_test_ keys for the sandbox and mk_live_ keys for production.

