Your API keys
- Keys are stored only as a SHA-256 hash. The full key is shown once, when you create it.
- Only workspace owners and admins can create or revoke keys, and revoking one stops it at once.
- A key reaches only its own workspace. Asking for another workspace’s account, post or media returns 404.
- 120 requests a minute per key, for REST and MCP together.