1. Invite a teammate
Create an invitation withPOST /projects/{project_reference}/invites:
invite-teammate.sh
2. Create a service key
Create a project-scoped service key withPOST /api-keys:
create-service-key.sh
key in the service’s secret store. Use its ID or prefix for identification; do not put the full key in logs or source control.
Verify the result
After the recipient accepts, list the project’s users and confirm the assigned role. For the service key, confirm the response reportsscope: "project" and the expected project_id.
Test the new key against a resource the service needs. If access fails, check both the key’s scopes and its owner’s project permissions.
External-service OAuth connections are separate from project membership. Configure them through the Integrations API.