Frontal is live.Read the announcement

Authentication

Authenticate people, applications, and CI jobs without widening access beyond the work they need to perform.

API keys authenticate applications to a workspace. Create a separate key for every integration or CI job, scope it to the smallest set of capabilities it needs, and store it in that environment's secret manager.

People and applications

People sign in with the access assigned to them. Applications use API keys. A key carries scopes; a person's role determines what they can see and approve. Neither should be used as a substitute for the other.

Rotation and incidents

Keys are shown once. Treat a key in source control, a ticket, or a screenshot as exposed: revoke it, create a replacement, update the integration, and confirm its first request succeeds. Keep the request ID from any failed call; it is the fastest way to investigate it.

See Security for the platform access model and API authentication for HTTP requests.

Updated Aug 31, 2026

© 2026 Frontal Labs, Inc. or its affiliates.

We measure site traffic without cookies by default. Accept to let us remember your visit across sessions, which makes our analytics more accurate.