Public API keys
Settings → Developers → API — create and manage workspace-scoped API keys for external integrations.
Use an API key when the integration isn’t an MCP client: a Zapier bridge, an internal service, a reporting job.
PRO access required — upgrade this workspace to Pro before issuing Public API keys. Admin access required — only workspace owners and admins can create or manage keys.
Creating a key
Section titled “Creating a key”Create key — issue a workspace-bound key with explicit scopes and a fixed expiry date.
| Field | Notes |
|---|---|
| Key name | e.g. Zapier CRM bridge. Required |
| Scopes | Grant only the minimum access required for this integration. At least one |
| Expiry date | All keys must expire. Recommended window: 30 to 90 days |
| IP allowlist | Optional. One IP or CIDR per line, or comma-separated — e.g. 203.0.113.10, 198.51.100.0/24 |
Available scopes
Section titled “Available scopes”Workspace access · Members access · Accounts access · Contacts access · Chats access / Chats write · Custom fields read / write · Messages read / Messages write · Tickets read / Tickets write.
Messages write sends Telegram messages as your accounts. Grant it only when the integration genuinely needs to send.
Storing the key
Section titled “Storing the key”The plaintext key is shown once:
Store this API key now — the plaintext key is shown only once. After closing this dialog only the prefix will remain visible. Store this key in your password manager or secret manager before closing the dialog.
Entergram stores only a hash of the key. There is no “show key again”.
Managing keys
Section titled “Managing keys”The list shows Active keys and Total keys, with status Active, Expired or
Revoked. Show archived ({n}) reveals retired keys.
Per key:
| Field | |
|---|---|
| Scopes | What it can do |
| Created / Created by | Provenance |
| Expires | Hard deadline |
| Last used | Never until first use |
| Usage | Request activity |
| Source IP | Where calls came from |
| User agent | No requests yet until first use |
| IP allowlist | Or No IP restrictions configured for this key |
Actions
Section titled “Actions”| Action | Effect |
|---|---|
| Copy key | Only while the one-time dialog is open |
| Rotate | ”The current key will be revoked and replaced with a newly generated key.” |
| Revoke | ”This key will stop working immediately for all clients using it.” |
| Docs | Opens the API reference |
Key lifecycle events are audited — Public API key created / rotated / revoked appear in Log history.
Rotation without downtime
Section titled “Rotation without downtime”Rotation revokes the old key at the moment the new one is issued, so plan for it:
- Create a second key with the same scopes.
- Deploy the new key to your integration.
- Verify traffic on the new key via Last used / Usage.
- Revoke the old key.
Using two keys and revoking the loser beats rotating a live key and racing the deploy.
Good practice
Section titled “Good practice”- One key per integration. Shared keys mean you can’t revoke one thing without breaking three others.
- 30–90 day expiry, as the app recommends. Forced rotation is the point.
- Always set an IP allowlist when the caller has a stable IP. It converts a leaked key from a disaster into a nuisance.
- Name keys after systems, not people.
- Check Last used before renewing. A key nobody uses is pure risk.
Troubleshooting
Section titled “Troubleshooting”| Message | Meaning |
|---|---|
| PRO access required | Upgrade the workspace |
| Admin access required | You’re not an owner or admin |
| Public API key management is temporarily unavailable | Transient — retry shortly |
| Public API hashing not configured | Server-side configuration issue — contact support |
| Public API storage not ready | A database migration is pending — contact support |
Related
Section titled “Related”- MCP connectors — for AI clients
- Privacy checklist
Cookie preferences
We respect your right to privacy. Choose which cookies to allow — your choice applies across our site. Cookie Policy
Required for the site to work, including remembering your privacy choices. Always on.
Help us understand which pages are popular and how visitors use the site.