Access keys
Create a service account for a script or integration, give it roles, and issue or revoke its keys.
A service account is how a script, an integration or a deployment job signs in. It acts with the permissions of the roles you give it, and its keys work only in this workspace.
Before you start: You need People & permissions at Can manage people or higher. You can only give a service account roles that grant no more than you hold.
Create a service account
- Open Team & Permissions › Access keys.
- Click New service account.
- Enter a Name that says what it is for, such as "CI deploy" or "Zapier".
- Click Create.
Give it a role
On the account's card, use the roles field (Give it a role…) to pick one or more roles. A service account never counts as an owner.
If it has no role, the card warns: "No role yet — its keys will authenticate but cannot read or change anything."
Create a key
- Click Keys on the account's card.
- Enter a New key name, such as "production".
- Click Create key.
- Copy the key straight away with Copy. The message says "Copy this key now — it won't be shown again."
Keys start with axk_. Use one as a Bearer token in the Authorization header. See the developer docs for how to call the API.
Important: The key is shown once. If you lose it, revoke it and create a new one.
Revoke a key
In the Keys panel, click Revoke beside a key. It is marked Revoked and stops working. Each key lists when it was created and when it was last used, or "never used".
Delete a service account
Click the X on its card and confirm Delete. Its keys stop working immediately.
What happens next
- A service account appears with a Service badge.
- Anything it does is recorded under its name, not under a person's.
- If a person who created keys is removed from the workspace, the keys they created stop working.
Tips
- Create a separate service account for each integration so you can revoke one without affecting the others.
- Give it a role that grants only what the integration needs.
- Keys only work for this workspace's own data, never for account-level pages such as your profile or security settings.
Troubleshooting
The key authenticates but every call is refused The account has no role, or its role does not allow that action. Add a role or check it with Access check.