Skip to main content
Omni Z-API groups the workspace security settings in the Administration → Security menu of the dashboard: Security. Only the workspace Owner can open this menu (see Team and roles).
Security menu in the Omni Z-API dashboard

Why use each one

  • API credentials: the Secret Key stays only on your server, and the Public Key can go to the browser without giving access to the API. If the Secret Key leaks, generate a new one and the previous one stops working.
  • IP restriction: a leaked Secret Key is useless outside your servers. Nobody can send messages, delete channels or change the webhook to receive your customers’ messages.
  • SDK authorized domains: prevents another website from using your Public Key to open the channel connection flow on your behalf.
  • Two-factor authentication: a leaked password is not enough to sign in to the dashboard, where the keys and workspace settings are.
  • Team and roles: each person gets only the access they need. Those who only follow along can’t change anything, and people who leave the team lose access when removed.
  • Audit log: shows who made each change, when and from which IP. It helps investigate a problem and prove what happened, with records that cannot be changed.
Start with the credentials: no API call is accepted without the Secret Key. The other settings are optional and add layers of protection.