Documentation
Open app

API keys

API keys authenticate approved machine-to-machine integrations. The first-party Configure Embed public deployment does not use an organization API key in the browser; it exchanges its publish/embed identity for a constrained guest session. If you only use chat or the built-in public widget, do not create a key for that purpose.

1

Open API Keys

Go to Console → Your org → API Keys in the left sidebar.

The API Keys screen listing keys with their public key, scope, status, last use and creation date
Each key shows its scope and whether it has ever been used.
2

Create a key

Click Create API Key (top-right). A dialog opens — enter an optional Name (e.g. "Production environment") to identify it later, then click Create.

The Create API Key dialog with a name entered
The name is only a label for you; it does not affect what the key can do.
3

Save the key and secret immediately

The "API Key created" screen is shown only once. It displays both the API Key (format: sota_ek_…) and the API Secret. Copy both now and store them securely — they cannot be retrieved after you close this screen.

The dialog shown once after creation, with the API key, the masked secret, and a warning that the secret will not be shown again
The secret is shown once. Copy it before closing this dialog.
4

Confirm and close

After saving, click I have saved the Secret to close the dialog.

5

Use the key in approved API calls

Use the key only with the machine API and scopes documented for your integration. Its main use is signing the ticket handshake that puts SotaAgents inside your own systems — see Embedding SotaAgents in your own systems. For a public guest widget, use Workspace → Configure Embed instead.

6

Disable a key

To stop using a key without deleting it, click the Actions button on the key's row and choose Disable. Confirm in the dialog. The key stops working immediately and remains visible in the list in a disabled state.

Keep keys secret

Never commit API keys to source control or share them in chat. Treat them like passwords. If a key is exposed, disable it immediately and create a new one.

Contents

Esc

Search titles and body text across every chapter.