[{"data":1,"prerenderedAt":76},["ShallowReactive",2],{"help-article-per-brand-integrations":3},{"data":4},{"title":5,"excerpt":6,"content":7,"help_category":8,"seo":11},"Per-Brand Integrations","Every connection in m18t belongs to one brand, chosen first in the wizard. Learn how that isolates publishing and how to share one API key across brands safely.","\u003Cp>\u003Cstrong>What you&#39;ll learn\u003C\u002Fstrong>\u003C\u002Fp>\n\u003Cul>\n\u003Cli>Why every connection in m18t belongs to exactly one brand — chosen first, before anything else.\u003C\u002Fli>\n\u003Cli>How that keeps one brand&#39;s content from publishing to another brand&#39;s CMS or social account.\u003C\u002Fli>\n\u003Cli>How to share a single API key across brands without weakening that separation.\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Chr>\n\u003Ch2>The concept: connections are brand-scoped\u003C\u002Fh2>\n\u003Cp>m18t is \u003Ca href=\"\u002Fhelp\u002Fbrand-vs-business\">multi-brand\u003C\u002Fa>. If you run Acme and Beta out of one workspace, the system has to make sure an Acme blog post can&#39;t land on Beta&#39;s Strapi, and a Beta caption can&#39;t post to Acme&#39;s Facebook Page. It does that by scoping every connection to a single brand.\u003C\u002Fp>\n\u003Cp>This isn&#39;t a setting buried at the end of a form — it&#39;s the \u003Cstrong>first\u003C\u002Fstrong> thing the connection wizard asks. Step one is &quot;Pick a brand.&quot; Credentials live in that brand&#39;s \u003Ca href=\"\u002Fhelp\u002Fthe-secret-vault\">Vault\u003C\u002Fa> context, and outlets (a Facebook Page, an Instagram account, a CMS instance) belong to that brand. When you publish a content piece, m18t looks at the piece&#39;s brand and only offers the connections that belong to it. The others don&#39;t appear.\u003C\u002Fp>\n\u003Cp>The result: switch the workspace to another brand and the publishing targets change with it. Same UI, a different brand&#39;s wiring.\u003C\u002Fp>\n\u003Ch2>Configuring a connection for a specific brand\u003C\u002Fh2>\n\u003Col>\n\u003Cli>Go to \u003Cstrong>Business Settings → Connections\u003C\u002Fstrong> (\u003Ccode>\u002Fstudio\u002Fbusiness\u002Fconnections\u003C\u002Fcode>).\u003C\u002Fli>\n\u003Cli>Click \u003Cstrong>Add Connection\u003C\u002Fstrong>.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Pick a brand\u003C\u002Fstrong> first — the wizard shows your brands as cards. Choose the one this connection serves. (A brand at its connection limit is marked \u003Cstrong>Full\u003C\u002Fstrong>; free a slot or review your plan on the Billing page.)\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Pick a provider\u003C\u002Fstrong>, then complete the setup, \u003Cstrong>Authentication\u003C\u002Fstrong> (\u003Ca href=\"\u002Fhelp\u002Fthe-secret-vault\">Vault\u003C\u002Fa> key), and — for Meta and Strapi — the \u003Cstrong>Outlets\u003C\u002Fstrong> step.\u003C\u002Fli>\n\u003Cli>Finish with \u003Cstrong>Create connection\u003C\u002Fstrong>.\u003C\u002Fli>\n\u003C\u002Fol>\n\u003Cp>The connection is now owned by that brand. Switch the workspace to a different brand and this connection won&#39;t appear as a publishing target there. (Editing a connection later lets you change its brand if you genuinely need to move it — but the normal model is one brand per connection.)\u003C\u002Fp>\n\u003Ch2>Sharing one key across brands\u003C\u002Fh2>\n\u003Cp>You&#39;ll often want several brands to use the \u003Cstrong>same\u003C\u002Fstrong> API key — one OpenAI account, say, to keep billing simple. m18t handles this without breaking brand separation, because the key in the \u003Ca href=\"\u002Fhelp\u002Fthe-secret-vault\">Vault\u003C\u002Fa> and the connection that uses it are two different things.\u003C\u002Fp>\n\u003Cp>A single connection belongs to one brand. But many connections — across different brands — can reference the \u003Cem>same\u003C\u002Fem> Vault key. So you create one connection per brand, each pointing at the shared key:\u003C\u002Fp>\n\u003Col>\n\u003Cli>Open \u003Cstrong>Add Connection\u003C\u002Fstrong>, pick \u003Cstrong>Brand A\u003C\u002Fstrong>, pick OpenAI.\u003C\u002Fli>\n\u003Cli>On the \u003Cstrong>Authentication\u003C\u002Fstrong> step, instead of adding a new key, select your existing one (e.g. \u003Ccode>OPENAI_API_KEY\u003C\u002Fcode>).\u003C\u002Fli>\n\u003Cli>Create the connection.\u003C\u002Fli>\n\u003Cli>Run \u003Cstrong>Add Connection\u003C\u002Fstrong> again, pick \u003Cstrong>Brand B\u003C\u002Fstrong>, pick OpenAI.\u003C\u002Fli>\n\u003Cli>On Authentication, select the \u003Cstrong>same\u003C\u002Fstrong> \u003Ccode>OPENAI_API_KEY\u003C\u002Fcode>.\u003C\u002Fli>\n\u003Cli>Create it.\u003C\u002Fli>\n\u003C\u002Fol>\n\u003Cp>\u003Cstrong>AI providers do not need this.\u003C\u002Fstrong> m18t&#39;s AI features read one workspace-level Vault key directly, so a single Gemini, OpenAI or Anthropic connection already serves every brand. The steps above matter for publishers and CMS connections, where routing genuinely is per brand.\u003C\u002Fp>\n\u003Cp>Now Brand A and Brand B each have their own connection record (so routing stays brand-scoped), but both resolve to one encrypted token in the Vault. Rotate that key once and both brands pick up the new value on their next call — see \u003Ca href=\"\u002Fhelp\u002Fthe-secret-vault\">The Secret Vault\u003C\u002Fa> for how rotation works.\u003C\u002Fp>\n\u003Ch2>Variations\u003C\u002Fh2>\n\u003Cul>\n\u003Cli>\u003Cstrong>Publishers stay isolated regardless.\u003C\u002Fstrong> Even when brands share an AI key, each brand&#39;s social and CMS \u003Cem>outlets\u003C\u002Fem> are its own — a shared OpenAI key never lets Brand A publish to Brand B&#39;s Page.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Per-environment too.\u003C\u002Fstrong> Within a brand, a connection is keyed by (brand, service, environment), so you can run Strapi-production and Strapi-staging side by side. See \u003Ca href=\"\u002Fhelp\u002Fconnect-strapi\">Connect Strapi\u003C\u002Fa>.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Agencies.\u003C\u002Fstrong> This is the model that makes \u003Ca href=\"\u002Ffor\u002Fagencies\">agency\u003C\u002Fa> work clean — each client is a brand with its own connections and (usually) its own client-owned keys. See \u003Ca href=\"\u002Fhelp\u002Fagency-mode\">Agency Mode\u003C\u002Fa>.\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Ch2>FAQ\u003C\u002Fh2>\n\u003Cp>\u003Cstrong>Can one connection serve two brands at once?\u003C\u002Fstrong>\nNo. A connection belongs to one brand. To use the same provider across brands, create one connection per brand — they can share a single Vault key.\u003C\u002Fp>\n\u003Cp>\u003Cstrong>If I share a key, can one brand accidentally publish to another&#39;s account?\u003C\u002Fstrong>\nNo. Sharing a key shares only the \u003Cem>credential\u003C\u002Fem>. Each brand&#39;s outlets (Pages, IG accounts, CMS instances) stay tied to that brand, so publishing routing is unaffected.\u003C\u002Fp>\n\u003Cp>\u003Cstrong>Why is a brand greyed out \u002F marked &quot;Full&quot; in the wizard?\u003C\u002Fstrong>\nThat brand has hit its connection limit for your plan. Remove an unused connection on that brand, or review usage on the Billing page to free a slot.\u003C\u002Fp>\n\u003Cp>\u003Cstrong>I set up a key but the AI button is disabled for this brand.\u003C\u002Fstrong>\nAI is the exception to the per-brand rule, so adding another connection will not help. AI features read a single workspace-level Vault key and their gate ignores brand entirely. Check instead that the connection is showing as healthy, and that its Purpose isn&#39;t restricted to a different kind of task. Publishing and CMS buttons are the ones that really are brand-scoped, and for those this answer does apply.\u003C\u002Fp>\n\u003Cp>\u003Cstrong>Can I move a connection from one brand to another?\u003C\u002Fstrong>\nEditing a connection lets you change its brand if needed. It&#39;s not the everyday path — the intended model is one brand per connection — but it&#39;s available for genuine moves.\u003C\u002Fp>\n\u003Cp>\u003Cstrong>What&#39;s next\u003C\u002Fstrong>\u003C\u002Fp>\n\u003Cul>\n\u003Cli>How keys are stored and rotated once: \u003Ca href=\"\u002Fhelp\u002Fthe-secret-vault\">The Secret Vault\u003C\u002Fa>.\u003C\u002Fli>\n\u003Cli>Why the keys are yours: \u003Ca href=\"\u002Fhelp\u002Fbyok-why-we-do-this\">Why m18t uses BYOK\u003C\u002Fa>.\u003C\u002Fli>\n\u003Cli>Brand structure overall: \u003Ca href=\"\u002Fhelp\u002Fbrand-vs-business\">Brand vs. Business\u003C\u002Fa> · \u003Ca href=\"\u002Fhelp\u002Fagency-mode\">Agency Mode\u003C\u002Fa>.\u003C\u002Fli>\n\u003C\u002Ful>\n",{"slug":9,"title":10},"connections-and-keys","Connections & API Keys",{"meta_title":12,"meta_description":6,"keywords":13,"canonical_url":14,"og_title":5,"og_description":15,"og_image":16,"robots":17,"json_ld":18},"Per-Brand Integrations | m18t Help","per-brand integrations, brand-scoped connections, shared api key, vault key reuse, publishing isolation, m18t connections, multi-brand keys","https:\u002F\u002Fm18t.com\u002Fhelp\u002Fper-brand-integrations","Connections are brand-scoped, picked first. Learn how that isolates publishing and how to share one key across brands.","https:\u002F\u002Fm18t.com\u002Fog-default.png","index, follow",{"@context":19,"@graph":20},"https:\u002F\u002Fschema.org",[21,35,60],{"@type":22,"headline":5,"description":6,"articleSection":10,"inLanguage":23,"datePublished":24,"dateModified":25,"image":16,"author":26,"publisher":30,"mainEntityOfPage":33},"Article","en","2026-06-25","2026-08-02",{"@type":27,"name":28,"url":29},"Organization","m18t","https:\u002F\u002Fm18t.com",{"@type":27,"name":28,"url":29,"logo":31},{"@type":32,"url":16},"ImageObject",{"@type":34,"@id":14},"WebPage",{"@type":36,"mainEntity":37},"FAQPage",[38,44,48,52,56],{"@type":39,"name":40,"acceptedAnswer":41},"Question","Can one connection serve two brands at once?",{"@type":42,"text":43},"Answer","No. A connection belongs to one brand. To use the same provider across brands, create one connection per brand — they can share a single Vault key.",{"@type":39,"name":45,"acceptedAnswer":46},"If I share a key, can one brand accidentally publish to another's account?",{"@type":42,"text":47},"No. Sharing a key shares only the credential. Each brand's outlets (Pages, IG accounts, CMS instances) stay tied to that brand, so publishing routing is unaffected.",{"@type":39,"name":49,"acceptedAnswer":50},"Why is a brand greyed out \u002F marked Full in the wizard?",{"@type":42,"text":51},"That brand has hit its connection limit for your plan. Remove an unused connection on that brand, or review usage on the Billing page to free a slot.",{"@type":39,"name":53,"acceptedAnswer":54},"I set up a key but the AI button is disabled for this brand.",{"@type":42,"text":55},"AI is the exception to the per-brand rule, so adding another connection will not help. AI features read a single workspace-level Vault key and their gate ignores brand entirely. Check instead that the connection is showing as healthy, and that its Purpose isn't restricted to a different kind of task. Publishing and CMS buttons are the ones that really are brand-scoped.",{"@type":39,"name":57,"acceptedAnswer":58},"Can I move a connection from one brand to another?",{"@type":42,"text":59},"Editing a connection lets you change its brand if needed. It's not the everyday path — the intended model is one brand per connection — but it's available for genuine moves.",{"@type":61,"itemListElement":62},"BreadcrumbList",[63,67,71,74],{"@type":64,"position":65,"name":66,"item":29},"ListItem",1,"Home",{"@type":64,"position":68,"name":69,"item":70},2,"Help","https:\u002F\u002Fm18t.com\u002Fhelp",{"@type":64,"position":72,"name":10,"item":73},3,"https:\u002F\u002Fm18t.com\u002Fhelp\u002Fcategories\u002Fconnections-and-keys",{"@type":64,"position":75,"name":5,"item":14},4,1786312169485]