API keys and connected apps are advanced connection tools.
Use them only when a trusted outside system needs to work with CoolFocus.
Ask:
• What system needs access?
• What work will it do?
• Who is responsible for it?
• When should access be reviewed or removed?
Only CoolFocus admins, or users with Integrations admin access, can view an integration's connection status, enable or disable it, or generate an API key. Anyone else who opens an integration's settings page sees it as forbidden.
When you enable an integration or regenerate its key, CoolFocus shows the full API key one time, right after the action completes. Copy it immediately and store it securely before you leave the page.
After that, CoolFocus only ever displays a masked version of the key (for example, the last 4 characters). There is no way to reveal the full key again later.
If you lose the key, click Regenerate on the integration's settings page. This creates a new key and immediately invalidates the old one, so update the outside system with the new key right away.
Each integration also has an App ID, which stays visible on the settings page and identifies which integration a key belongs to. It is not a secret on its own; the API key is what authenticates calls.
Treat API keys like passwords. Do not share them in email or chat. Remove access when it is no longer needed.