API authentication and rate limits
Use a dedicated API token for each integration and grant only the scopes it needs. Send it as a Bearer token over HTTPS and keep it on your server, never in frontend JavaScript or a public repository.
The API applies rate limits to protect the workspace and live control plane. Cache read-heavy data, use webhooks for changes where possible, and back off when a request returns a rate-limit response. Retrying immediately can make an incident worse.
Use a test workspace for destructive actions such as deleting recordings, rotating keys or stopping destinations. Log the endpoint, status and request ID, but redact tokens and private URLs. Revoke a token from Settings → API tokens when an integration is retired or exposed.