Workspace settings

API keys and integrations

Updated August 17, 2026

Two cards in Settings cover this: Integrations for API keys and webhooks, and Connected apps for app authorizations.

Creating an API key. Open Settings, then Integrations, then press New API key. Give it a name so you remember what it is for, and press Create.

The key is shown once. Copy it before closing the dialog. It cannot be recovered afterwards, and the table only ever shows the key prefix. If you lose it, revoke it and make a new one.

The keys table shows Name, Key prefix, Created, Last used and Status. Last used is genuinely useful for spotting keys nothing is calling any more.

Revoking is immediate and permanent. Press the trash icon and confirm. Anything using that key stops working straight away, including connections built with it. The row stays in the table marked Revoked, for your records.

Webhooks push events out to a URL you choose. Press Add endpoint, paste the endpoint URL, and select the events you want. You can pick individual events or choose all events.

A signing secret is shown once, at creation, exactly like an API key. Your receiver uses it to verify that the signed POST really came from you.

Each endpoint shows its health. OK with the time of the last success, Failing with the time of the last failure, or a note that there have been no deliveries yet.

Failing endpoints are paused automatically. After repeated failures the endpoint is marked Auto-disabled. Fix the receiving end, then re-enable it with the refresh button. You can also toggle any endpoint between Active and Off yourself, or delete it.

You can be emailed when an endpoint is auto-disabled. That toggle is in Notifications and privacy, see Your account settings.

Connected apps is the other card. It shows apps authorized on your account through a connector, along with the URL you paste into the app to connect it.

Each connection lists the app name, when it was connected, when it was last used, and what access it holds. Access is shown in plain language: reading your account, making guarded changes you approve, and staying connected without re-signing in.

Revoke removes access immediately. Confirm by name and that app is disconnected on the spot. You can reconnect it later. Disconnect all revokes every connection at once.

Recent activity is an audit trail of the most recent actions connected apps have taken on your account, so you can see what has actually been done rather than only what was permitted.