Give automation a deliberate identity.
API keys let the CLI, integrations, and agents work with Telos without sharing a person's password or full account access.
Name the consumer and choose its boundary
Open Settings → API keys, give the key a name, and select the capabilities the consumer needs. A key cannot grant more access than the person creating it, and organisation administration and credential management stay with people.
Select only the capabilities the consumer needs, such as read access to opportunities. Explicit selection keeps every key's boundary visible and reviewable.
Make access easy to review and remove
Set an expiry when the connection is temporary. Create separate named keys for separate consumers so usage is attributable and a compromised or retired connection can be removed without interrupting the others. The full key is shown only when it is created, so copy it into the consumer then.
Connect the surfaces that need Telos truth
Use an API key for the Telos CLI, an external integration, or an agent that should read and write approved work. Review the name, permissions, last use, and expiry in Settings; delete a key when its consumer no longer needs access.