Developers

API keys

Keys scope a caller to one workspace. A key issued to a sub-account reaches that sub-account's templates and documents and nothing else.

What you get

A workspace has a key and a secret. The key identifies the workspace; the secret authenticates the caller. Both are created when the workspace is first provisioned.

The secret is shown once

Only a hash of the secret is stored, so it cannot be read back — not by you and not by us. Copy it when it is displayed. If it is lost, rotate: there is no recovery path, by design.

Rotating

POST /api/v1/workspaces/keys/rotate issues a fresh pair and returns the new secret once. Rotate on a schedule, and immediately if a key has been exposed in a log, a repository or a screenshot.

Scope

Keys are per workspace, and a workspace maps to one CRM sub-account or to an agency. There is no account-wide key that reaches every sub-account, which means a leaked key is bounded by the workspace it belongs to.

Handling

  • Send the secret in a header, never a query string — URLs end up in logs.
  • Keep it in your platform's secret store rather than in source.
  • Use separate workspaces, and so separate keys, for test and production.
  • Rotate when someone with access leaves.

Calls from the CRM

The workflow action does not use an API key. Those calls are signed by the CRM and verified against that signature, so a workflow never needs a secret pasted into it.