Platform
API keys for inbound webhooks

Workspaces can create and revoke API keys for inbound webhook traffic, so an external system can post into Yada without sharing a login.
Create named live keys from settings
Revoke a key without rotating everything else
A hard cap on active keys keeps the list manageable
Keys authenticate inbound webhook calls only