← All help articles

Apps & connections

API keys & bot tokens, explained

Where each value comes from

Every credential field in your dashboard tells you where its value comes from, but here's the short version by channel:

  • Slack: your Bot Token, App-Level Token, and optional Signing Secret all come from your Slack app at api.slack.com/apps. See Connect Slack for the full setup.
  • Telegram: the default flow needs no token at all — only the Advanced own-bot path needs one, which comes from BotFather when you create your bot. See Connect Telegram.
  • Voice: your ElevenLabs key comes from your ElevenLabs profile, your Groq key comes from the Groq console, and your OpenAI key comes from the OpenAI dashboard.
  • WhatsApp: the Phone Number ID comes from WhatsApp → API Setup in your Meta app, the access token comes from Meta Business Settings, the app secret comes from App Settings → Basic in your Meta App dashboard, and the verify token is any string you invent yourself.
  • Bring your own model key (BYOK): a key from a provider like OpenRouter, MiniMax, or Kimi. See BYOK: bring your own key for details.

How credentials are stored

Credentials are encrypted before they're stored, and every secret field has a reveal toggle so you can double-check what you entered. Once saved, don't share these tokens in chat or email — paste them directly into the connection field instead.

Ready to get started?
Free for 7 days. No card required.
Start free →

Related articles

BYOK: bring your own keyWhat bring-your-own-key means, how it's priced, and why your model provider's own terms still apply.