CollabOS supports personal and workspace API keys.
Key creation
When a key is created, CollabOS returns the plaintext API key once. Store it securely at creation time. Later list responses expose only safe metadata such as the prefix and last four characters.
If scopes is omitted, CollabOS applies the appropriate default scope set. An explicitly empty scope array is rejected.
Keys can optionally expire. Expiry must be in the future and may be at most two years from creation.
Access requirements
Personal API-key and webhook management requires CollabOS Premium.
Workspace API-key and webhook management is available to active workspace owners/admins when the workspace has an eligible CollabOS workspace product.
Storage
Store API keys in a secret manager or server environment variable. Do not put them in browser storage, frontend bundles, Git repositories, screenshots, support tickets, or analytics payloads.
Revocation
Revoke a key when it is no longer needed or may have been exposed. A revoked key can no longer authenticate API requests.
Treat API keys like passwords. Create separate keys for separate services or environments so one compromised key does not expose every integration.