Limit an API key to specific workspaces
When you provision an API key you can now choose which workspaces it may reach, alongside the read/write areas you were already able to pick. A key limited this way answers 403 Forbidden for any request that touches a workspace outside its list — including a fetch by id such as GET /api/v2/contacts/:id, where the workspace never appears in the path — and GET /api/v2/teams/:team_id/workspaces lists only the workspaces it was given.
This is the same restriction the OAuth connection flow already offered, so an integration you build once no longer has to be trusted with every workspace on the team to do its job in one of them. The same choice is offered when you create a platform application, for the default API key it comes with. Keys you have already issued are unchanged and keep their existing access; the limit applies only when you choose it at creation.
Agent examples: give an agent a key scoped to one client's workspace · hand a contractor a key that cannot see the rest of the team.
Resources: Workspace · Fetch Contact