Requirements: Admin role.
- Go into Settings → API keys.
- Read the notice at the top — it reminds you this key acts with administrator permissions.
- Follow the same procedure as a personal key (section 4, steps 2-8): name, allowed origins, expiration, what the key can do, email code, show-once.
Result: the company keys table adds two columns the personal table doesn’t have: “Created by” (the email of who generated it — useful for auditing, even though the key acts as a generic admin) and “Allowed origins” (section 6).
