Skip to main content
Grant human access with a project invitation and give a service its own project-scoped API key. Use an API credential authorized to manage access. A valid API key does not necessarily have permission to invite members or create other keys.

1. Invite a teammate

Create an invitation with POST /projects/{project_reference}/invites:
invite-teammate.sh
The response describes a pending invitation. It does not mean the recipient has accepted it.

2. Create a service key

Create a project-scoped service key with POST /api-keys:
create-service-key.sh
Save the returned key in the service’s secret store. Use its ID or prefix for identification; do not put the full key in logs or source control.

Verify the result

After the recipient accepts, list the project’s users and confirm the assigned role. For the service key, confirm the response reports scope: "project" and the expected project_id. Test the new key against a resource the service needs. If access fails, check both the key’s scopes and its owner’s project permissions. External-service OAuth connections are separate from project membership. Configure them through the Integrations API.

API references