We considered using API Keys but they can't be limited. Would someone be able to change our configuration and everything else with an API Key or can we safely use it to extract all user emails?
Hi,
Welcome to the community
If the API Key is tied to a admin account, someone could make any change allowed by REST API, so is not the best option to share the same API token with different user.
You must be a registered user to add a comment. If you've already registered, sign in. Otherwise, register and sign in.