Omni Z-API groups the workspace security settings in the Administration → Security menu of the dashboard: Security. Only the workspace Owner can open this menu (see Team and roles).
Why use each one
- API credentials: the Secret Key stays only on your server, and the Public Key can go to the browser without giving access to the API. If the Secret Key leaks, generate a new one and the previous one stops working.
- IP restriction: a leaked Secret Key is useless outside your servers. Nobody can send messages, delete channels or change the webhook to receive your customers’ messages.
- SDK authorized domains: prevents another website from using your Public Key to open the channel connection flow on your behalf.
- Two-factor authentication: a leaked password is not enough to sign in to the dashboard, where the keys and workspace settings are.
- Team and roles: each person gets only the access they need. Those who only follow along can’t change anything, and people who leave the team lose access when removed.
- Audit log: shows who made each change, when and from which IP. It helps investigate a problem and prove what happened, with records that cannot be changed.
Start with the credentials: no API call is accepted without the Secret Key. The other settings are optional and add layers of protection.