Per-company API keys
The owner or an administrator creates a key under Integrations, read-only or read-write, with an expiry date. Send it in the Authorization: Bearer header. A key can be revoked at any time and stops working if its creator is deactivated.