Skip to main content
Secure how your team signs in, control programmatic access, and understand how Bizzy protects your data.

Sign-in security

Passkeys

Phishing-resistant sign-in with device biometrics

Two-Factor Authentication

TOTP codes and backup codes

Key Management

Bizzy uses API Keys for REST API access from backend services, scripts, and integrations. API key management requires the Owner role.

API Keys

Create keys for REST API integrations
AI agents (Claude, Cursor, Windsurf, etc.) connect through the MCP server, which uses its own authentication flow rather than API keys.

Data protection

Data Protection

Isolation, encryption in transit, AI data access, deletion and recovery

Security Best Practices

  • Principle of least privilege: Grant only the permissions each key needs
  • Separate keys per integration: Create dedicated keys for each service or agent
  • Regular audits: Review and revoke unused keys monthly
  • Secure storage: Never commit keys to version control; use environment variables
Last modified on June 12, 2026