User API keys
User keys provide scoped access to supported external endpoints. They do not replace browser sessions, bypass personal ownership or grant site administration. Optional key support requires its documented schema and enabled server capability.
Create and manage a key
In settings, choose the intended personal/team scope, expiration and supported permissions. Review before creating. The secret is shown once; store it securely and do not include it in public URLs, source code, logs or screenshots. The server stores a verifier rather than a recoverable secret.
Use the endpoint's documented authorization header and an explicitly supported operation. A team key must respect its role and billing scope; switching the browser's team does not rewrite an existing key. Revoke unused or compromised keys. Expired/revoked keys must stop working at the server.
Lists, creation confirmations, key details, errors and revocation labels support English and Chinese. The secret, key identifier and raw recorded evidence are never translated. An API language choice affects presentation only.
The normal preview does not silently enable every optional migration. Prepare a separate acceptance database and test ownership, scope, expiration, revocation and request limits before exposing a new endpoint. Detailed implementation and original verification are available in the Chinese guide.