Help Center / Identities & Workspaces / Use API tokens safely

Use API tokens safely

Scope API tokens to identities and permissions for safer automation.

Updated: 2026-02-26

Token safety model

API tokens should be scoped tightly by identity and app permissions.

Best practices

  • Create separate tokens per automation.
  • Use write scope only when required.
  • Rotate tokens on schedule.
  • Revoke tokens immediately if exposed.

Operational check

Audit token usage and identity bindings regularly to prevent permission drift.

More in Identities & Workspaces