API & Integrations
API authentication
Authenticate API requests with a workspace-scoped token.
API requests are authenticated with a bearer token generated from Workspace Settings, scoped to a single workspace and to the permissions of the member who created it. Tokens can be revoked at any time without affecting any other integration.
For server-to-server integrations that should not be tied to an individual member's account, bot accounts provide a dedicated identity with its own token and permission set, described in the Bot accounts article.