User sessions
Protected personal and organization actions require an end-user bearer token. Refresh tokens rotate; never put them in URLs or client logs.
Authentication & Scopes
End-user sessions and integration keys serve different purposes and must remain separate.
Protected personal and organization actions require an end-user bearer token. Refresh tokens rotate; never put them in URLs or client logs.
Create keys through the authenticated developer API. The supported self-service key scope is marketplace.view. Secret values are shown only at creation.
X-Tenant-Id selects an active organization membership; it never grants membership. The API rechecks the resource and role on each request.
Use a separately configured test environment. Production access requires technical review and provider approval where applicable.
Back to developer guides