> ## Documentation Index
> Fetch the complete documentation index at: https://developer.omni.z-api.io/llms.txt
> Use this file to discover all available pages before exploring further.

# Security

> Protect access to the API and to your Omni Z-API account

export const frontendUrl = 'https://app.omni.z-api.io';

export const projectName = 'Omni Z-API';

{projectName} groups the workspace security settings in the **Administration → Security** menu of the dashboard: [Security](https://app.omni.z-api.io/app/security). Only the workspace **Owner** can open this menu (see [Team and roles](/en/security/team)).

<Frame>
  <img src="https://mintcdn.com/omni-z-api/q9hmNrF61s-W1Xyg/images/security-overview.png?fit=max&auto=format&n=q9hmNrF61s-W1Xyg&q=85&s=c28af084dce91567539377070877728b" alt="Security menu in the Omni Z-API dashboard" width="2278" height="924" data-path="images/security-overview.png" />
</Frame>

| Setting | What it protects | Where |
| - | - | - |
| [API credentials](/en/authentication) | Authentication of API calls with Public Key and Secret Key | **Security → API Credentials** |
| [IP restriction](/en/security/ip-restriction) | Which IPs can call the API with the Secret Key | **Security → IP Restriction** |
| [SDK authorized domains](/en/security/sdk-domains) | Which websites can open the channel connection SDK | **Security → SDK Configuration** |
| [Two-factor authentication](/en/security/two-factor) | Dashboard login | **My account → Security and compliance** |
| [Team and roles](/en/security/team) | Who accesses the workspace and what each person can do | **Administration → Team** |
| [Audit log](/en/security/audit) | History of who did what in the workspace | **Administration → Audit log** |

## Why use each one

* **API credentials:** the Secret Key stays only on your server, and the Public Key can go to the browser without giving access to the API. If the Secret Key leaks, generate a new one and the previous one stops working.
* **IP restriction:** a leaked Secret Key is useless outside your servers. Nobody can send messages, delete channels or change the webhook to receive your customers' messages.
* **SDK authorized domains:** prevents another website from using your Public Key to open the channel connection flow on your behalf.
* **Two-factor authentication:** a leaked password is not enough to sign in to the dashboard, where the keys and workspace settings are.
* **Team and roles:** each person gets only the access they need. Those who only follow along can't change anything, and people who leave the team lose access when removed.
* **Audit log:** shows who made each change, when and from which IP. It helps investigate a problem and prove what happened, with records that cannot be changed.

<Tip>
  Start with the credentials: no API call is accepted without the Secret Key. The other settings are optional and add layers of protection.
</Tip>


This documentation is built and hosted on [Mintlify](https://mintlify.com), a developer documentation platform.