A practical checklist for replacing a one-time-view API key across MCP clients and verifying calendar access.
CalendarMCP shows a newly created or rotated API key once. If you lose the value, rotate it and update every MCP client that uses it.
Inventory the clients using the key: desktop assistants, coding tools, automations, and deployed agents. Decide where the replacement value will live. A password manager or secret manager is better than a screenshot, chat message, or checked-in configuration file. The dashboard warns that the old key stops working immediately when you rotate it.
list_calendars.list_calendarsis a low-impact verification step. It returns each available calendar's account, enabled state, and per-calendar permissions. It does not create or edit an event. If the old key is still configured, the client will fail authentication before the tool can run.
Rotating a CalendarMCP API key is not the same as disconnecting a Google account or changing a calendar grant. Check the dashboard separately if your goal is to remove an account or narrow the calendars an agent may access.
Sources: CalendarMCP security changelog and CalendarMCP tool documentation.
Connect your Google Calendar to Claude and any MCP client in about two minutes.
Connect Google Calendar