API keys

The API uses bearer tokens. A key is shown once, at the moment it is created, and stored only as a hash — there is no screen that can show it to you again.

Scope

Give each integration its own key. Revoking one integration's access should never mean rotating everyone else's.

If a key leaks

Revoke it. Revocation takes effect on the next request; there is no grace period and no way to un-revoke. Create a replacement and update the integration.