Settings
The organization's name and slug, its members and invitations, and the keys, webhooks and MCP connections it runs on.
Settings has four sections.
| Section | Who can see it | Holds |
|---|---|---|
| General | Everyone. Only admins and owners can edit | Picture, name, slug, your chat accounts, and the danger zone |
| Billing | Admins and owners | Plan, credits, add-ons and invoices. See Billing |
| Members | Everyone sees the member list. Admins and owners also see Invitations and the controls on each row | People, roles and invitations |
| API | Admins and owners | Median keys, webhooks and MCP connections |
The full permission matrix is in Roles.
General
| Row | Rules | Controls |
|---|---|---|
| Picture | PNG, JPEG, WebP, GIF or AVIF, up to 4 MB. Set it here only, not from the API | The organization’s picture in the dashboard, such as the organization switcher |
| Name | 2 to 60 characters | The name in the dashboard, the widget, email replies and the help site |
| Slug | 3 to 32 characters. Lowercase letters, numbers and single dashes. Unique across Median | The help site address, and the first email support address |
Name and slug save when you press Enter or leave the field. Esc puts the saved value back. A member sees the rows locked, with “Only admins and owners can change these settings.”
| Error | Cause |
|---|---|
| Enter an organization name. | The name is empty |
| Use at least 2 characters for the organization name. | The name is too short |
| Enter an organization slug. | The slug is empty |
| Use at least 3 characters for the slug. | The slug is too short |
| Slugs can only use lowercase letters, numbers, and dashes. | The slug has another character, such as _ or a space |
| “acme” is already taken. Try another one. | Another organization has that slug |
| This slug is reserved. Choose a different one. | The slug is a reserved word, such as admin, api, help, support or www |
| Use single dashes between letters or numbers. | The slug starts or ends with a dash, or has two in a row |
| Choose a PNG, JPEG, WebP, GIF, or AVIF image. | The picture is another format, such as SVG |
| Choose an image no larger than 4 MB. | The picture is too large |
What the slug controls
| Address | Form | After you change the slug |
|---|---|---|
| Site | https://<slug>.median.website |
Moves to the new slug at once. The old address returns 404 |
| Email support | <slug>.support@median.sh |
Unchanged. The address is fixed the first time email support is turned on |
The old slug is free for another organization to take once you change it.
Chat accounts
Lists the Slack and Discord accounts you linked to the assistant. Only your own accounts are listed. Each row shows the platform and when it was linked, with Unlink. After unlinking, messages from that account stop reaching the assistant until you link it again. To link an account, see Work from Slack and Discord.
Danger zone
| Row | Who | Does |
|---|---|---|
| Leave this organization | Everyone | Leave removes your access. You need a new invitation to get back in |
| Delete this organization | Owners, including co-owners | Press Delete, type the organization’s exact name, then press Delete organization. Permanently deletes the organization and all its data |
- The last owner cannot leave. The page says “Assign another owner before leaving this organization.” Make someone else an owner first.
- A mistyped name leaves Delete organization disabled.
- Deleting cancels the paid plan and its add-ons immediately. If billing can’t be checked or the plan can’t be cancelled, nothing is deleted and the dialog says “Your subscription couldn’t be checked or cancelled, so nothing was deleted. Try again in a moment.”
Members
The list shows everyone in the organization with their role. The line above the list counts them, such as “4 people in this organization.” or “You are the only member.” Admins and owners get a role menu and Remove on each row they can manage.
The roles are Owner, Admin and Member. What each can do, who can change whom, and the errors are in Roles.
- A role you cannot hand out is greyed out in the menu.
- A role change applies to the person’s next action.
- Remove asks first, then takes their access immediately. Their messages stay.
Invite someone
Open the dialog
Press Invite members in the Invitations section.
Fill it in
Enter an Email and pick a Role. The role starts at Member.
Send
Press Send invitation. The dialog stays open and says who was invited, so you can send another. Press Done to close it.
Each pending invitation shows the address, the role and who sent it.
| Button | Does |
|---|---|
| Copy link | Copies the invitation link. Anyone holding it can open the invitation, but only the invited address can accept it |
| Resend | Sends the email again. The expiry does not reset |
| Revoke | Asks first. The link stops working. You can invite the same address again later |
If the email fails, the row reads “Email did not send:” with the reason and “Copy the link instead.” The invitation still works through Copy link.
| Rule | Value |
|---|---|
| Expiry | 14 days after it was first sent. Expired invitations leave the list |
| Pending invitations | 100 per organization |
| Inviting an owner | Owners only. Admins can invite admins and members |
| Accepting | Signed in with the invited email address. Accepting switches you into the organization |
| Organizations per person | 50 |
| Sending and resending | Rate limited per organization. See Rate limits |
| Message | Cause |
|---|---|
| jane@acme.com is already in this organization. | The address belongs to a member |
| You are already in this organization. | You invited your own address |
| jane@acme.com has already been invited. Resend it from the list. | A live invitation exists. Use Resend |
| You can have 100 invitations out at once. Revoke one to make room. | 100 are pending |
| Only an owner can invite somebody as owner. | An admin picked Owner |
| This invitation expired. Send a new invitation. | Resend pressed after the invitation passed 14 days, for example on a page left open. Invite the address again. An expired invitation leaves the list and does not block a new one |
| Too many requests. Wait a moment and try again. | Too many invitation emails in a short time |
The person invited may see these.
| Message | Cause |
|---|---|
| This invitation is no longer valid | Used, revoked, older than 14 days, or the organization was deleted. Ask for a new one |
| This invitation is for jane@acme.com | They are signed in with another address. Sign out and back in with the invited one |
| You can be in 50 organizations at once. Leave one to make room. | They already belong to 50 organizations |
API
Median keys
One key pair covers the widget, the API, identity, tools and webhooks. See Authentication.
Create
Press Create key. Name (optional) takes up to 40 characters. Left empty, the key is named “Median key” and a number.
Copy both values
Copy your keys shows the pair once. Try the widget opens the live widget on the new public key in a new tab.
| Label | Starts with | Goes |
|---|---|---|
| Median key · server only | median_key_ |
MEDIAN_KEY on your server, and nowhere else |
| Public key · safe for the browser | median_pk_ |
The widget’s apiKey |
- Each row shows the name, both keys masked, the creation date and when it was last used.
- Up to 10 keys per organization. At 10 the button reads Key limit reached, and the API answers “You have reached the limit of 10 Median keys. Revoke an unused key before creating another.”
- Give each environment its own key. Use the public key and the identity signature from the same Median key.
Revoke asks first, then Revoke key. It cannot be undone. Your other keys keep working.
| Uses the revoked key | Result |
|---|---|
| Widget with its public key | Hidden. The console says Median did not recognize the apiKey |
| API calls | Refused |
| Identity signatures | Stop verifying |
| Tool endpoints connected with it | Syncs fail until you reconnect the route with a live key |
| Webhook endpoints signed with it | Signatures stop matching. Remove the endpoint and add it again |
Webhooks
Add
Press Add endpoint. Enter the URL.
Pick events
Every event starts on. Use a group’s switch, a single event’s switch, or Select all and Clear.
Save
Press Add endpoint.
| Group | Event | Label |
|---|---|---|
| Inbox | message.created |
New message |
| Inbox | conversation.created |
New conversation |
| Inbox | conversation.updated |
Conversation updated |
| Bugs and suggestions | bug.created |
New bug |
| Bugs and suggestions | suggestion.created |
New suggestion |
| Bugs and suggestions | signal.updated |
Bug or suggestion updated |
| Knowledge | knowledge.suggestion.created |
New knowledge suggestion |
- An endpoint signs with the newest Median key at the time you add it.
- Each row shows the URL, its events, and “delivered”, “failing since” or “no deliveries yet”.
- Edit changes the URL and events. Remove stops every delivery, retries included.
- A failing endpoint also shows on the home page under Needs fixing.
- Payloads, the signature check and retries are in Webhooks.
| Message | Cause |
|---|---|
| Create a Median key above before adding a webhook. That key verifies this endpoint’s deliveries. | The organization has no Median key |
| Enter a valid URL. | The URL cannot be parsed |
| Endpoints have to use HTTPS. | The URL is http. For local work, put an HTTPS tunnel in front of your receiver |
| Endpoints have to use a public internet address. | The host is private or local |
| Endpoint URLs cannot include credentials. | The URL has a user name or password |
| Endpoint URLs have to be 512 characters or fewer. | The URL is too long |
| Select at least one event. | Every event is off |
| You can hold 10 endpoints at once. Remove one to make room. | 10 endpoints exist |
MCP
MCP server URL is https://api.median.sh/mcp. Add it to your client, then
approve access in Median. Scripts can send a Median key as a bearer token
instead. See MCP server.
The list shows every client anyone in the organization has connected, up to the 50 newest. Each row has the client’s name, who approved it, and when it was last used.
- A connection acts as the person who approved it. Their role is checked on every call.
- Disconnect asks first. The client is signed out on its next request. Reconnecting needs approval again.