Only Admins can create or revoke API keys
SecurityCreating and revoking an organization's API keys (the credential for the public REST API) now requires the Admin role. Previously, any signed-in Member could create or revoke a key; that gap is closed.
Members keep read-only access to the API keys card: they can still see each key's name, obfuscated value, and last-used date, but the New key form and the Revoke button no longer appear for them.
If a Member needs to issue or revoke a key, an Admin has to do it, or promote them first.
See Members for the Admin/Member split, and Authentication for how API keys work.
Updated later
As of 2026-07-16, creating or revoking keys is gated by the API keys: Edit permission, not the Admin role by name. The built-in Admin still holds that permission, but you can now grant it to any custom role too, so "requires the Admin role" above now means "requires anyone with API keys: Edit". Viewing the list needs API keys: View (or Edit). See Roles.