# Manage workspace API keys

Create a scoped API key, store its one-time token, and revoke it when it is no longer needed.

## Before you start

### Intended audience

Workspace managers and operators who configure local or API access.

### Required permissions

You need workspace-manager access to API key settings. The API key owner needs an active responder seat for any key with a write scope.


### Prerequisites

- Know the integration purpose and its minimum required scopes.

## Procedure

<a id="phase-create-the-key"></a>

### Create the key

<a id="step-open-api-keys"></a>

1. **Open API keys.** Open Settings. Select API keys.

<a id="step-start-a-key"></a>

2. **Start a key.** Select Create API key. Enter a purpose-specific name.

<a id="step-choose-a-preset"></a>

3. **Choose a preset.** Select a preset when it matches the task. Review every included scope.

<a id="step-set-expiration"></a>

4. **Set expiration.** Set the shortest practical expiration before you change individual scopes.

<a id="step-limit-the-scopes"></a>

5. **Limit the scopes.** Keep only the required scopes. Do not grant write access for a read-only integration.

![API key form with preset, expiration, and scope controls.](https://tellagen.com/help/assets/manage-api-key-form.webp)

Set expiration and review the preset scopes before you create the key.

<a id="step-create-and-store-the-token"></a>

6. **Create and store the token.** Select Create key. Store the token immediately because Tellagen shows it once.

<a id="phase-review-and-revoke"></a>

### Review and revoke

<a id="step-find-an-existing-key"></a>

7. **Find an existing key.** Use the key list filters to find Active, Expired, or Inactive keys.

<a id="step-revoke-a-key"></a>

8. **Revoke a key.** Open the key's actions. Select Revoke. Confirm the exact key. Tellagen marks it Inactive.

## You are done when…

The integration has a minimum-scope token, and the key list shows its current lifecycle state.

## Troubleshooting

<a id="troubleshooting-the-key-cannot-be-created"></a>

### The key cannot be created.

Enter a Name and select at least one scope. Keep write scopes with an active responder owner.

<a id="troubleshooting-the-one-time-token-was-not-stored"></a>

### The one-time token was not stored.

The unseen key remains Active until you revoke it. Find the exact key, revoke it and create a replacement. Store the new token securely. Never copy it into a ticket, timeline event, or public document.

<a id="troubleshooting-a-request-returns-a-scope-error"></a>

### A request returns a scope error.

Use the [API Reference](https://tellagen.com/api-reference#scopes) to identify the required scope. Create a replacement key with that scope.

## Related articles

- **Recommended next task:** [Run a local Diagnosis for an incident](https://tellagen.com/help/run-local-diagnosis)
- [Use the public API reference](https://tellagen.com/help/use-public-api-reference)


## Continue through the incident lifecycle

- **Next task:** [Configure Codex for Tellagen Diagnosis](https://tellagen.com/help/configure-codex-for-diagnosis)
- [Back to Support Center](https://tellagen.com/help#help-search)

## Last verified date

2026-08-29
