Skip to main content

API Keys and Connected Apps

Use API keys and connected apps carefully when outside systems need access.

Written by Jonathan Marbutt

API keys and connected apps are advanced connection tools.

Use them only when a trusted outside system needs to work with CoolFocus.


Before You Create Access

Ask:

  • What system needs access?

  • What work will it do?

  • Who is responsible for it?

  • When should access be reviewed or removed?


Who Can Manage Keys

Only CoolFocus admins, or users with Integrations admin access, can view an integration's connection status, enable or disable it, or generate an API key. Anyone else who opens an integration's settings page sees it as forbidden.


The API Key Is Shown Only Once

When you enable an integration or regenerate its key, CoolFocus shows the full API key one time, right after the action completes. Copy it immediately and store it securely before you leave the page.

After that, CoolFocus only ever displays a masked version of the key (for example, the last 4 characters). There is no way to reveal the full key again later.

If you lose the key, click Regenerate on the integration's settings page. This creates a new key and immediately invalidates the old one, so update the outside system with the new key right away.

Each integration is also tied to a stable App ID, but you will not see or manage it in CoolFocus. CoolFocus and the integration partner already share that identifier directly. The only credential shown on the settings page is your API key, and it is what authenticates calls.


Best Practice

Treat API keys like passwords. Do not share them in email or chat. Remove access when it is no longer needed.

Did this answer your question?