Skip to content

Security

Security Center

Rotate keys, review sessions, audit access and enforce 2FA.

Updated Jul 15, 2026API 2026-07-01 Edit on GitHubReport an issue

API key rotation

Rotate any key without downtime — the old secret keeps working for a 24-hour overlap window before it is revoked.

Sessions

Review every active dashboard session with device, IP and last active time. Revoke individually or globally.

Audit logs

Every privileged action (key created, webhook rotated, settings changed) is written to an append-only audit log with actor, IP and diff.

Allowed IPs & domains

Restrict keys to specific IP ranges and browser origins. Requests from other sources are rejected with 403 access_denied.

OAuth apps

Manage third-party apps connected via OAuth, review scopes and revoke access at any time.

Two-factor auth

Enforce TOTP or WebAuthn for every seat on the account. Backup codes are shown once at enrolment.