Use least privilege
Scopes are messages:read, messages:write, calls:read, calls:write, and resources:read. Keys may additionally restrict numbers and bots.
Rotate and revoke
Secrets are shown once. Use separate keys for integrations and revoke keys you no longer need. Live keys must never appear in frontend code.
Organisation boundaries
Each key is bound to its organisation and environment. Requests use the organisation OAuth account configured in CRM OAuth Setup; scopes and resource restrictions narrow its CRM permissions.
Pilot access requires verified organisation configuration. Never expose a live API key in frontend code.