Best GEO Software
All posts
By Best GEO Software Teamtools

How to Use Read-Only Promptwatch API Keys for Looker Studio and MCP

Create org or project read-only keys, copy them once, and use them for Looker Studio and MCP clients that must not publish.

A read-only key can still see citations and visitor analytics. It can also see crawler analytics when the project is on Professional, Business, or a self-serve agency plan with a crawler allowance. Read-only changes permissions, not plan access. Write actions are what disappear. An API key that can publish to Webflow does not belong in Looker Studio or a shared Claude project.

Promptwatch issues org-level and project-level keys, including read-only. Read-only is the default for reporting and for MCP assistants that should only ask questions. Create a project-level read-only key and copy it once. Store it in the same place you store other tokens. Do not paste it into a public ticket.

Site: promptwatch.com. MCP and API access are included on Essential ($95/mo, 7-day trial). Explore is free (ChatGPT, 10 prompts). Looker (Data Studio) is listed on Professional ($245/mo), Business ($579/mo), and agency Kick-off $199 / Growth $399 / Scale $799. Promptwatch is 4.7/5 on G2, 1,840+ brands.

Do not buy a second product for "API access." It is already on Essential. Professional and agency plans add the Data Studio listing.

Project for one brand, org for the book

A project key sees one project. An org key sees every project. Use a project key for a brand Looker report or a Cursor window that should not see other clients. Use an org key when an internal analyst is allowed to query the whole book, and only if every project on the org is allowed in that report. Prefer a project key per client dashboard. Agencies that share one org key in a contractor ChatGPT thread will leak a second brand the first time someone asks "list projects."

The "list projects" failure mode is the one that catches agencies. A contractor with an org key can ask the assistant to enumerate every project on the account, and the assistant will. The org key does not know which projects the contractor is allowed to see. It only knows the key is valid for the org. A project key cannot enumerate anything outside its project, which is why it is the right shape for a contractor thread.

What the key hides, and where you paste it

On MCP, a read-only key hides write tools. The assistant can still use read tools: visibility and sentiment series, citations including Reddit and YouTube, prompts and responses, competitor heatmaps, content gaps, query fan-outs, site health, and visitor analytics. Crawler analytics also appear when the project's plan includes them. Essential has no listed crawler-log allowance.

It cannot manage prompts, tags, topics, or personas, generate content, work Content Agent slots, push drafts or publish to a CMS, or create reports and action items. Confirm write tools are absent by asking the assistant to publish or create a prompt. It should not be able to.

That confirmation step is worth doing once. A read-only key that was misconfigured as write-capable will quietly let the assistant publish, and the only way you find out is when a draft lands in the CMS. Ask the assistant to do a write action before you hand the key to a contractor. If it refuses, the key is read-only. If it does not, rotate the key and recreate it.

Looker only pulls data. Authenticate the Promptwatch connector with a read-only key anyway if you are on Professional, Business, or an agency plan. People reuse secrets. The same string will end up in MCP next month. A read-only key in Looker is cheap insurance against that reuse.

Write-capable keys stay on a laptop or a secrets manager for the people who are supposed to publish. Keep any write-capable key out of shared workspaces. The official ChatGPT plugin and Claude connector talk to the same hosted MCP server. Give those listings a read-only key unless the user is your content lead. OpenAI's crawler docs are still the bot-access rule for ChatGPT Search. On Professional, Business, or a self-serve agency plan, a read-only key can show whether those bots appear in Agent Analytics. It will not change robots.txt.

Same REST API behind both

Looker: add the connector, authenticate with the key, start from monitor/citation/prompt/visibility templates, 90-day pull windows, auto-refresh from Data Studio settings. MCP: add the hosted streamable HTTP URL in Claude, Cursor, ChatGPT/Codex, or another client; OAuth or Bearer. Add the same class of key (or OAuth) to Claude or Cursor MCP.

The 90-day pull window is the default Looker shape. A longer history needs a separate pull or a stored export. Plan for that before the QBR, not during it.

Otterly.AI from $29/mo and Peec AI from $95/mo do not replace this key model. Ahrefs Brand Radar from $199/mo plus Ahrefs is index research. Method: how we rank. Tools list.

FAQ

Does a read-only key hide citations and crawler analytics?

No. It still sees citations and visitor analytics. It also sees crawler analytics when the project is on Professional, Business, or a self-serve agency plan. Essential has no listed crawler-log allowance. Write actions are what disappear.

Project key or org key for a client Looker report?

Project key. An org key sees every project. Agencies that share one org key in a contractor ChatGPT thread will leak a second brand the first time someone asks "list projects."

Which plan includes API keys?

MCP and API access are included on Essential ($95/mo). Looker Studio is listed on Professional, Business, and the agency plans.