Account

Security and access

Sign-in, roles, keys, and what admins can see.

Sign-in is Google or a one-time email link; there are no passwords to manage. Roles are admin and producer; only admins change billing, plans, integrations, API keys and team settings. API keys act as the admin who created them and stop working if that admin leaves. Integration secrets (webhook signing secret, HubSpot token) are stored server-side and never shown again. Birdray staff can enter a workspace to help when you ask; that access is logged.