api-keyssecuritysetupmcp

How to Rotate a CalendarMCP API Key Without Losing Your Agents

A practical checklist for replacing a one-time-view API key across MCP clients and verifying calendar access.

Sarah Chen
Developer Relations, CalendarMCP ·

CalendarMCP shows a newly created or rotated API key once. If you lose the value, rotate it and update every MCP client that uses it.

Before rotating

Inventory the clients using the key: desktop assistants, coding tools, automations, and deployed agents. Decide where the replacement value will live. A password manager or secret manager is better than a screenshot, chat message, or checked-in configuration file. The dashboard warns that the old key stops working immediately when you rotate it.

Rotation checklist

  1. Open the CalendarMCP dashboard and choose Rotate API key.
  2. Copy the replacement at creation time and store it securely.
  3. Update the bearer token in each client configuration.
  4. Reconnect each client and call list_calendars.
  5. Confirm the expected accounts and Read/Write grants before making a write.

list_calendarsis a low-impact verification step. It returns each available calendar's account, enabled state, and per-calendar permissions. It does not create or edit an event. If the old key is still configured, the client will fail authentication before the tool can run.

What rotation does not do

Rotating a CalendarMCP API key is not the same as disconnecting a Google account or changing a calendar grant. Check the dashboard separately if your goal is to remove an account or narrow the calendars an agent may access.

Sources: CalendarMCP security changelog and CalendarMCP tool documentation.

Ready to get started?

Connect your Google Calendar to Claude and any MCP client in about two minutes.

Connect Google Calendar