Skip to main content
Create a dedicated workspace API key for each integration and grant only the required scopes. Send API keys as Authorization: Bearer $RISOS_API_KEY. Keep them server-side, rotate them per integration, and revoke compromised or retired keys immediately.