vq_ws_.
Creating a credential
1
Open the automation console
Sign in to Vaquill and go to Automation in the sidebar. You must be an owner of the organization; members cannot provision API access.
2
Enable the Workspace API
This creates an installation owned by your organization, not by you personally. It keeps working if you later leave the organization.
3
Create a credential
Give it a name that says what will use it, for example
billing-sync or intake-bot. Choose an expiry.vq_ws_ credential cannot call them. That is deliberate. A credential that could mint credentials would make revoking one meaningless.
There is no rotate operation. Rotating means issuing a second credential, deploying it, then revoking the first, which is the same sequence with none of the ambiguity about which one is live.
Credential properties
The last six characters are a checksum, so a truncated or mistyped credential is rejected before it reaches our database. If you get
invalid-credential immediately on a key you just pasted, check for a copy that cut off the end.Scopes
A credential carries scopes in the formresource:action. Write implies read on the same resource; run does not, so a reporting integration can be given read access without the ability to start billable work.
These are every scope that governs at least one operation. Measured from the route registry on 2026-09-06: 37 of them, across 133 operations.
403 tells you exactly what is missing.
Three further names are accepted when you mint a credential and govern nothing:
credentials:rotate, webhooks:read and webhooks:write. Granting one is harmless and grants nothing. They are not features in progress: rotation is deliberately a two-credential sequence you run yourself, and outbound webhooks were cut, so polling the operation resource is the only completion signal. The names stay accepted because the taxonomy is frozen, not because something is coming.chronology:read and chronology:write govern the matter timeline and are separate from matters:* on purpose. matters:write means “create and rename matters”; a customer who granted that has not agreed to let a credential edit a timeline a lawyer curated.nda:* and compliance:* are their own pairs rather than a reuse of review:*. An NDA triage is not a contract review, and a credential restricted to reviews must not get triages by implication. research:* means the chat and legal-research surface, not document screening.facts and summaries have read and run but no write, so there is no scope that grants editing a generated fact or summary. documents:write implies documents:read but never documents:download.Folders have no scope of their own. They are governed by
matters:read and matters:write, because a folder is an organizing device for matter work rather than a resource in its own right.documents:download is separate from documents:read on purpose. Listing document metadata and pulling an original confidential file are different risks, so an integration that only checks ingestion status need not be able to retrieve originals.403 with an insufficient-scope problem document naming the scopes it needed.
Attributing actions to a person
If the work your integration does is initiated by one of your users, send their identifier:400 acting-user-rejected rather than repaired, because a shortened or scrubbed identifier is a different identifier presented as your assertion.
Revoking
Revoke from the automation console or withDELETE /api/v1/workspace/credentials/{credentialId}. Revocation takes effect immediately, including for requests already in flight against a cached credential.
