qeda-logo

DocsManage your Workspace

API access / personal access tokens

Settings → Developer Access: generating and scoping tokens for the Qeda platform API — a different thing from AI Hub's API keys.

Settings → Developer Access is for tokens that authenticate against the Qeda platform API — managing projects and deployments programmatically. That's a different token from AI Hub's API Keys (covered in Secure your App), which only call the AI API; the two aren't interchangeable.

The Developer Access page with no API tokens yet
A fresh account starts with none — same "nothing until you create it" convention as workspaces and API keys elsewhere in this app.

Generating a token

Generation only asks for a name. A new token starts with Read-only access — Write has to be turned on afterward, not chosen at creation.

The "Generate New Token" dialog with a Token Name field
No permission picker here — every new token defaults to Read-only.
The API Tokens list showing two tokens with different permissions, masked keys, and action icons
Same masked-by-default pattern as AI Hub: eye to reveal, copy, a kebab for rights, and delete.

Scoping with Read/Write

"Manage Rights," from a token's kebab menu, is the only way to add Write access after the fact — two checkboxes, nothing more granular than that (no per-project or per-endpoint scoping yet).

The "Manage Rights" dialog with Read and Write checkboxes, both checked
A Read-only token can't deploy or change anything — Write is what turns it into a full automation credential.

Note. There's no platform API for these tokens to authenticate against yet — generating one produces a real-looking key with no backend behind it. The scoping model here (Read vs. Write, revoke anytime) is what will apply once that API ships, so treat a Write token the same way you'd treat a password once it does: scope it down, and revoke it (trash icon) the moment it's no longer in use.