# Teams & access keys

## Personal team and shared teams

Every Lune account starts with a **personal team** that's just you. It holds
your daily allowance, your credits, and the access keys you create in it. You
can't delete it.

To share a paid plan or work with other people, create a **team**:

1. Click the team switcher at the bottom left of the dashboard and choose
   **New team**. This opens **Settings → Teams**.
2. Click **New team**, pick a name, and click **Create**.

Each team has its own plan, credit balance, and member list. You can belong to
any number of teams, own up to 20, and
switch between them from the same menu.

## Roles inside a team

| Role   | Can do                                                              |
| ------ | ------------------------------------------------------------------- |
| Owner  | Everything: billing, plan changes, members, deleting the team.      |
| Admin  | Billing, plan changes, and inviting members (but not other admins). |
| Member | Use the team's plan and credits; can't change billing.              |

Members share the team's allowance and credits, and any member can buy
credits. Only owners and admins can change the plan or cancel it, and only
owners can remove other members.

## Which team pays

- **Apps you connect by signing in** (OAuth: ChatGPT, Claude, Grok, and the
  rest) always bill your personal team. Its plan, credits, and Sources settings
  apply, whichever team the dashboard has selected.
- **An access key** bills the team it was created in.
- **The dashboard's own tools** (Assistant, Critique, Workspace, Papers, and
  Profiles) bill the team selected in the team switcher.

To use a shared team's plan from an AI app, create an access key while that team
is selected and connect the app with the key.

## Access keys

An access key is a secret that starts with `lune_`. Apps that can't sign you in
through the browser use one, and so does the local stdio server. The dashboard
shows a key once, when you create it, so copy it somewhere safe right away.

Create keys on the
[Credentials page](https://luneresearch.com/dashboard/settings/credentials)
(**API keys** tab, **New key**) with the team you want selected. One key per
device or app lets you revoke just the key on a lost laptop.

Keys created in the dashboard carry the four default
[scopes](https://luneresearch.com/docs/concepts/scopes) and never expire. The
[command line app](https://luneresearch.com/docs/cli) can create a key with other scopes or an expiry
date.

Members see and revoke only their own keys. Owners and admins see every key in
the team and can revoke the ones people created, which helps when someone
leaves.

## When a key is revoked

Calls made with the key start failing within five minutes. The app shows an
error or asks you to sign in. Create a new key and put it where the old one
was.

## Switching teams

The team switcher at the bottom left of the dashboard sets the team you work in
on that device: which keys, billing, and Sources you see, and which team the
dashboard's own tools bill. It doesn't change which team a connected app
bills. In the command line app, `lune teams use <slug>` sets the team that
`lune keys create` creates keys in, for the current profile. Running
`lune login` again resets it to the team the new sign-in bills.
