Connecting an AI agent is safe when you understand what your API key does and you keep a review step in front of every change.
Your key carries unrestricted read and write access to every project and record in your workspace. It does not unlock anything you could not already see yourself, but anyone holding it has that same access. Treat it like the password to your accounting system.
Two approaches, and the right one depends on who else can see the Project.
If the key lives in Project knowledge, keep that Project to yourself. Do not put an unrestricted key into a Project shared with contractors, assistants or team members who should not have full write access.
Never paste it into a third-party tool, a browser extension or a website. The only place it belongs is the authorization header on a request to tools.flipperforce.com.
Nothing runs in the background. There are no scheduled jobs and no webhooks, so FlipperForce never pushes your data anywhere on its own. Every request happens because you asked for it in that conversation.
Records deleted through the API cannot be recovered. Never give an agent a blanket instruction to delete. Name the specific record, and confirm it yourself first.
You share a screen recording, hand off a laptop, remove a team member, or suspect it has been exposed. Request a replacement through the integrations page, or email support@flipperforce.com and we will help.