Create and manage API keys
Create a key with the right scopes, store it safely, see when it was last used and revoke it.
Create a key
- Go to Settings → API keys and click New API key.
- Name it after the integration that will use it, e.g. Zapier automation or Website lead form.
- Tick only the Scopes it needs (see scopes).
- Click Create key.
- Copy your API key — this is the only time the full key is shown. Vatli stores only a hash and can never show it again. Click Done.

Treat a key like a password. Don’t put it in website JavaScript, a public repository or a mobile app — anyone with the key can act on your workspace within its scopes. Call the API from your server.
See how a key is used
Each key in the list shows its scopes, when it was Created, when it was last used (or “never used”), and an expiry date if it has one.
Revoke a key
Click Revoke next to the key. It stops working on its next request. Revoked keys stay in the list (marked Revoked) as an audit trail. If you lose a key, revoke it and create a new one.
Agents and Viewers
Members without the API permission see “Ask an admin to create one.” Admins can grant the API keys & webhooks permission to a specific member — see Custom permissions.