Access and API keys

Give people and agents exactly what they need.

Organization roles, website-scoped collaborators, and API keys you can scope to a single website and revoke instantly. Every operation is tenant-isolated and audited.

  • Unlimited members on paid plans
  • Org- or site-scoped API keys
  • Audited, tenant-isolated operations

Access that matches how you actually work.

Roles that mean something

Owner, admin, and member, with billing authority and deletion reserved for the people who should hold them.

Website-scoped collaborators

Invite someone to one website rather than your whole organization. A contractor sees the project they are on and nothing else.

Content-only access

Let a client edit their own copy and publish items without giving them the ability to change the website itself.

Scoped API keys

Keys are limited to one organization or one website, with read or full-edit access, and can be rotated or revoked at any moment.

Keys cannot spend

An API key can never hold the owner role, so no integration and no agent can change what you are billed.

Audit history

Publishes, rollbacks, access changes, and key activity are recorded, so there is always an answer to who did what.

Isolation is structural, not a setting.

The old way

With Cactal

One shared login passed around the team

Named members with roles, and unlimited seats on paid plans

A contractor who can see every client you have

A collaborator scoped to a single website

One all-powerful API key in an environment file

Keys scoped per website, read-only where that is enough

Hoping a tenant boundary was applied everywhere

Isolation enforced at the platform, on every operation

Access and security questions

Have a security review to run? Talk to us. Talk to us.

Unlimited on every paid plan. Charging per seat would mean deciding who does not get an account, which is a bad way to run a website.

No. Collaborator access is scoped per website. Someone invited to one website sees that website only, and organizations are strictly isolated from each other.

Revoke or rotate it immediately and it stops working at once. Scope keys narrowly in the first place and the blast radius of a leak is one website, with read access if that is all it needed.

On enterprise terms. SSO, SLA, and compliance requirements vary enough that we scope them per agreement rather than selling them as checkboxes. Bring your requirements to the first conversation.

Connect your agent and build your first site free

Give it a try and experience the agent-native website platform for yourself.