API keys

Servers and some AI clients authenticate with a bearer key. AI clients that
support OAuth can instead connect as a signed-in person, with no key to copy.
Owners and admins create and revoke workspace keys from Settings → AI & agents.
Keep keys secret.

Create a key

Select Create an API key, name it, and tag the environment it serves —
Development, Staging or Production. Twelfth shows a newly created key
only once: copy it immediately.

The Connect an agent key flow creates a key for you. This path is for the
things that have no connector to click through — a cron job, a script, your own
backend. OAuth-capable assistants can connect through sign-in instead.

One key per thing

Give every device, server and automation its own key. It costs nothing, and it
is the difference between revoking one stale laptop and taking production down
with it. Each row shows the key’s prefix, when it was last used, its activity
over the last twelve weeks, and — once it has connected — the client and version
on the other end. A row that reports more than one client is a key being shared;
split it.

Rename a connection or change its environment from the row’s menu at any time.
Neither reissues the secret, so nothing that is already connected breaks.

Revoke a key if it’s exposed

Revoke a key immediately if a device is lost, a team member no longer needs the connection, or you suspect the key was exposed. Revocation stops any AI connection using that key immediately.