API authentication and rate limits

Use a dedicated API token for each integration and grant only the scopes it needs. Send it as a Bearer token over HTTPS and keep it on your server, never in frontend JavaScript or a public repository.

The API applies rate limits to protect the workspace and live control plane. Cache read-heavy data, use webhooks for changes where possible, and back off when a request returns a rate-limit response. Retrying immediately can make an incident worse.

Use a test workspace for destructive actions such as deleting recordings, rotating keys or stopping destinations. Log the endpoint, status and request ID, but redact tokens and private URLs. Revoke a token from Settings → API tokens when an integration is retired or exposed.

Was this helpful?

← Back to Help Centre