Skip to content

API keys

An API key authenticates GraphQL requests as the member who created it. The token starts with tpx_, is shown once at creation, and is stored only as a hash. A lost token cannot be recovered. API access is available on every plan.

Send the full token in Authorization, with no Bearer prefix. Regional endpoints are on API overview.

Authorization: tpx_<token>

Any member creates keys under Settings → API keys. A workspace administrator also sees every member’s active keys under Settings → Integrations.

One key per integration keeps revocation surgical. The token belongs in a secret manager or an environment variable, not in source control, tickets, or chat.

Any member lists their own active keys on Settings → API keys. A workspace administrator lists every key in the workspace on Settings → Integrations. lastUsedAt on each key updates roughly hourly, not on every request.

At creation, access is read-only, write-only, or full access. New keys default to read-only. A key carries the permissions of the member who created it. Scope narrows those permissions and never widens them. Scope is fixed at creation.

Access in the app Scope stored on the key
Read-only *:read
Write-only *:write
Full access *:read and *:write

A read-only key that calls a mutation is rejected with API_KEY_SCOPE_DENIED. See Conventions.

Any member revokes their own keys. A workspace administrator revokes any key in the workspace.

Deactivating a member revokes all of that member’s active keys. Reactivating the member does not restore them. See Members.

Revocation is recorded immediately. Authorizer results can stay cached for about 30 seconds, so a just-revoked token may still be accepted briefly.