Managing API keys
Create and revoke read-only delivery keys for headless integrations.
Create keys for the delivery API under Settings → API keys.
Notes
- Keys are read-only and scoped to the current workspace's published content.
- A key is shown once at creation — copy it then; only a hash is stored.
- Revoke a key any time to immediately cut off access.
- Managing keys requires the admin role or above.
Treat keys like passwords: don't commit them to public repos, and rotate them if exposed.