Skip to main content

Account API Keys

An account API key lets an integration act with your account's access. On Workspace requests, the key's selected scopes and your current Member permissions both apply. A key does not grant you access to a Workspace you have not joined.

An integration that must operate across an organization's current and future Workspaces uses a different credential: see Organization API Keys.

Create an account key​

  1. Open Account → Apps → API Keys.
  2. Choose Create API Key and enter a name that identifies the integration.
  3. Select the scopes it needs. Use read scopes for an integration that only reads data; add write scopes only for the operations it must perform.
  4. Choose an expiration.
  5. Create the key and copy the secret immediately. The full key is shown only once.

If your account's Apps page does not show the API Keys tab, contact support.

Store the secret​

Keep the key in an environment variable or a secrets manager. Never commit it to source control, put it in a public Site or browser bundle, or include it in logs. Share access through your secrets manager rather than sending the key in a message.

Use the Authentication guide for request headers and API examples. The CLI guide explains non-interactive authentication from your terminal.

Review and revoke keys​

Return to Account → Apps → API Keys to review your keys, their scopes, expiry, and last use. Revoke keys that are no longer required. A revoked key cannot authenticate new requests; update the integration with a replacement credential when rotating a key.

Existing keys created in a Workspace​

Existing workspace-created keys remain supported. Manage them under that Workspace's Settings → API Keys. They use their owning account's memberships and selected scopes; creating a key on a Workspace page does not make it a single-Workspace access boundary.

This guide uses account keys for account-owned integrations. It does not change or revoke an existing key.