Settings

Workspace configuration

General

Security

Require MFA for all team members

Members must enable multi-factor authentication to access the workspace

Session timeout

Automatically log out inactive sessions after 24 hours

IP allowlist enforcement

Restrict workspace access to approved IP ranges only

Audit log retention — 90 days

Keep full audit history for compliance and debugging

Notifications

Failed login alerts

Email alerts when repeated login failures are detected

Rate limit warnings

Notify when an application approaches token limits

API key expiry reminders

7-day and 1-day reminders before keys expire

Provider sync failures

Alert when an identity provider sync fails

Danger Zone

Reset all API keys

Immediately revoke all active API keys. Applications will lose access until new keys are issued.

Delete workspace

Permanently delete this workspace and all associated data. This action cannot be undone.