API keys

Creating keys, permission levels, and scoping a key to specific resources.

API keys let a program do what you can do in the app. Create them under Settings → API keys.

Creating a key

Name it for where it will be used. The secret is shown once; store it somewhere safe, because it cannot be shown again.

Ownership

A key belongs either to you — acting as you — or to a service, for programs that should not be tied to a person who might leave.

Permission levels

Custom permissions

Choose actions — create, read, update, delete, add version — and the resources they apply to: document, section, tab, category, directory, API key, path, task.

Prefer Custom over All. A key that only reads documents cannot delete a directory if it leaks.

Revoking

Delete a key and it stops working immediately. Do that rather than rotating a secret you think may have been exposed.

Next