← Auth / Security

API keys

auth / security · features

Issuing an API key — machine (headless) access to the platform: it authenticates the Public API, and in the next version — MCP v2. The feature's peculiarity isn't the length of the path but its shape: one creation dialog, into which three doors lead. A user issues a key for themselves from their own profile (self-issuance, without choosing a user); an Owner / Admin issues a key for an employee from the shared key list or from a specific employee's card (issuance, with typeahead). All doors converge on one creation dialog, which exists as a single copy. Self-issuance is the main path, administrator issuance is auxiliary; a key is never wider than its owner's permissions.

Flow · self-issuance (user)
Profile Account start · own account
"Create key" · without choosing a user
API Key Create dialog · self-issuance form
Flow · issuance (Owner / Admin)
API Keys start · oversight, issuance to an employee
"Create key" · employee search
targeted User Card from the card · employee prefilled
API Key Create dialog · issuance form + picker