One credential, one workspace
Every API key and every OAuth connection belongs to exactly one workspace, and can only ever read or change that workspace:- A key is created inside a workspace (Settings → API & MCP) and keeps belonging to it, even if the person who created it leaves.
- An OAuth connection is approved for a workspace. The consent screen asks which one, and only offers workspaces where you are an owner or admin.
- If you run several workspaces, create one key per workspace. There is no cross-workspace key.
GET /v1/me:
Response 200
Members, roles and what a key can do
People join a workspace with a role: owner, admin, supervisor, chatter or content assistant. Only owners and admins can create API keys, approve OAuth connections, and see or revoke the workspace’s keys and connected apps.credential.kind is api_key or oauth (a connected app’s token), credential.scopes always includes the implicit workspace:read, and credential.creatorIds is null when the credential can see every creator. rateLimit is the general limit for this credential.
A credential does not inherit anyone’s role. What it can do is exactly:
- its scopes (see Authentication), narrowed by
- its creator restriction, if it has one.
Timezone
Each workspace has a timezone (for exampleEurope/London or America/New_York), shown in GET /v1/me. The API uses it wherever a “day” matters:
GET /v1/stats/todaymeans today in the workspace timezone.- Daily series in revenue and overview reports are split at local midnight.
startandenddates (YYYY-MM-DD) in report windows are local dates.
createdAt, lastMessageAt, and so on) are always UTC, with milliseconds and a Z suffix, for example 2026-09-26T14:02:31.000Z. Change the workspace timezone in the dashboard’s workspace settings.
Isolation between workspaces
Workspaces never see each other’s data. If you ask for an id that belongs to another workspace, the API answers404 with the same body it gives for an id that never existed. It never tells you that the id exists somewhere else. The same rule protects creators outside a key’s creator restriction.
A suspended workspace gets 403 WORKSPACE_SUSPENDED on every call until the suspension is lifted.
Ids
Every object has a stable id with a prefix that says what it is. Always take ids from API responses; never build them yourself.
A fan is per creator: the same person subscribed to two of your creators is two fans with two ids.
Related
- Creators: the accounts inside a workspace.
- Authentication: creating keys and approving apps.
- Security: how workspace data is protected.