You manage API keys on the API access page in the customer portal, under the API section (/app/{your-company}/api-access).
Creating a key
Give the key a name and, optionally, a product scope — the set of products it's allowed to call. A key created for a single product will be rejected if used against any other, which is a simple way to limit blast radius for a particular integration or environment.
When you create a key, the full value is shown once. Copy it immediately and store it securely — only a prefix and the last four characters are shown afterward.
Managing keys
For each key you can see its prefix, last-4, scope, and when it was last used. You can:
- Enable / disable a key without deleting it.
- Revoke a key permanently.
- Create as many keys as you need — one per environment or integration is a good pattern.
Permissions
Who can manage keys depends on the member's tenant role. Members with the Manage API keys ability (owners and admins) manage all of the company's keys; other members see only their own. See Inviting team members and roles.
Next
Related articles
Still need help?
Our team is happy to help with integration or billing questions.