Endpoint
Create an API key
- Open the Developer Portal.
- Select your team.
- Go to API keys.
- Create or reset an API key.
- Copy the generated key immediately. It is shown once.
api_.
Authentication errors
Every method, includinginitialize, requires the API key. Authentication failures return HTTP 200 with JSON-RPC error code -32001, not an HTTP 401. The message distinguishes missing or malformed credentials from a key that was parsed but rejected:
API key is not valid. Check that the client sends Authorization: Bearer <API_KEY> and copies the complete key from secure storage. Keys are shown only once; if yours is lost, generate a new key and update every client using the old one. The endpoint only accepts POST; GET returns HTTP 405 with allow: POST, OPTIONS.
Connect your client
Replaceapi_... with the API key you copied from the Developer Portal. Codex and Cursor read the key from the WORLD_DEVELOPER_API_KEY environment variable at startup, so set it persistently (for example, in your shell profile, loaded from a secrets manager) rather than with a one-off export. VS Code prompts for the key once and stores it securely.
- Claude Code
- Codex
- Cursor
- VS Code
Available tools
Recommended flow
Start every session by asking the assistant to inspect the team:Images
Useupload_app_image for app store images. It uploads the image and stores the correct filename in the matching metadata field.
The tool accepts either:
source_url: a public HTTPS URL to a PNG or JPEG.image_base64: base64-encoded PNG or JPEG bytes for local files.
configure_mini_app for Mini App text, links, categories, permissions, countries, and languages. Use upload_app_image for logo, content card, meta tag, hero, and showcase assets.
Review submission still requires image metadata. Upload the required images before calling submit_app_for_review:
Timeouts and retries
A timeout or dropped connection doesn’t tell you whether a call went through, and these tools don’t replay the original result. Re-read state (get_world_id_signing_key, get_world_id_registration_status, get_app_config) before you retry:
configure_world_idandrotate_world_id_signing_key: the private key is only in the original response. If that response is lost, the key is unrecoverable, but the portal still applies its signer address. Retryingconfigure_world_idreturns the existing registration withsigning_key: null. Retryingrotate_world_id_signing_keyfails with-32004(rotation_in_progress) until the registration status isregisteredagain. Ifget_world_id_signing_keyshows a signer address you don’t hold, wait untilget_world_id_registration_statusreportsregistered, then rotate again from a trusted channel (see Security notes).submit_app_for_review: if the first call went through, a retry fails with-32004Only unverified apps can be submitted.Checkget_app_configfor the review status instead.
Security notes
- Store generated World ID private keys immediately. They are returned once and are not recoverable from the portal.
configure_world_idandrotate_world_id_signing_keyreturn the private key as a tool call result, not a one-time dialog — it passes through the assistant’s model context and, depending on the client, may be persisted in session transcripts or debug logs. Treat it as sensitive. If it was generated through a client whose logs aren’t under your team’s control, don’t just rotate again from that same client — the replacement key would leak through the identical path. Rotate from the Developer Portal dashboard instead: it generates the new key in your browser and sends only the signer address.- Keep API keys out of files you commit. Claude Code’s
--scope projectwrites the header to.mcp.json, which is meant to be committed; the examples above use local scope, an environment variable, or an input prompt instead. - Use a separate API key per local agent or project when possible.
- Delete or rotate API keys that are no longer needed.
- Confirm destructive actions before asking the assistant to rotate a signer key or submit an app for review.