Authentication & Scopes

Give each integration only the access it needs.

End-user sessions and integration keys serve different purposes and must remain separate.

User sessions

Protected personal and organization actions require an end-user bearer token. Refresh tokens rotate; never put them in URLs or client logs.

Integration keys

Create keys through the authenticated developer API. The supported self-service key scope is marketplace.view. Secret values are shown only at creation.

Organization context

X-Tenant-Id selects an active organization membership; it never grants membership. The API rechecks the resource and role on each request.

Use a separately configured test environment. Production access requires technical review and provider approval where applicable.

Back to developer guides