Workspaces
Every account has a default Personal Workspace. Existing resources that used the user’s stable account ID remain available through a compatibility layer, while newly created workspaces use generatedws_... identifiers.
Create and list workspaces
id in CSV and other workspace-specific routes. Names and slugs may change and must not be treated as authorization identifiers.
Workspace roles apply only inside the shared workspace. A user who is a Viewer in another person’s workspace retains normal permissions in their own workspace.
Viewer collaborators can use a personal API key to read resources explicitly shared through the workspace even when their personal plan does not grant unrelated standalone API compute.
Dynamic enforcement
Tokens do not permanently encode workspace privileges. Every request checks the current membership and role. Removing a collaborator immediately removes access for that token on its next request. UseGET /api/v1/me/access to inspect effective workspace access without returning any credentials.
See Workspace collaboration for the complete permission vocabulary, resource-specific scope, and collaborator lifecycle.