Scoped keys. Passkeys. Everything logged.
An API for your jobs, candidates, pipeline and agent, with keys that can never do more than you can. Two-factor for the whole team, and an audit log that names who or what acted.
How it works.
Keys that follow your role
Each key holds explicit scopes and is checked against your live role on every request. Wildcards never include sensitive scopes like billing, audit or email bodies. Revoke takes effect on the next call.


Passkeys and required 2FA
Face ID, Touch ID or a hardware key as the strongest factor, authenticator apps as the second. Admins can require a factor for everyone, enforced in the backend across dashboard, API and agent.


An audit log that knows the difference
Every action is recorded and filterable by session, API key or authorized application. When something changed, you know whether it was a colleague or an integration.


Nothing privileged by credential
Inviting members, changing billing and issuing credentials are done by a person in the dashboard, never by a key or an app. Security changes ask you to confirm it is you first.
Setup guide in the docsDiscover more features
Get started
Find your perfect weirdo
The person who would fail anywhere else and belongs with you. Tell us the role and we will show you who the agent would go after first.
