Create and rotate API keys
API keys authenticate server-to-server requests. Treat them like passwords: keep them on your backend, limit who can view them, and rotate them on a schedule.Create a key
- Open Settings → API keys.
- Select Create API key and give it a purpose-based name, such as
production-sync. - Copy the secret immediately and store it in your server’s secret manager.
- Send it using the
Authorization: Bearer <your-key>header.