Account Administration
Organization housekeeping: adding people, securing the account, and tracking what you spend. None of it is needed to make your first API call — if you have not made one yet, start with the Quick Start Guide and come back when you need something here.
All of it happens in the Toolpath API Portal. The Engine API has no account management endpoints of its own.
Invite teammates
Invite people from the Team page with Invite Teammate. Only people who need to generate and distribute API keys need an account here — the Engine API authenticates with the key alone, so the developers and services that use a key do not each need to be team members.
Teammates are invited as member or admin.
Members get a read-only view of the shared account. They can see the team's API keys and the organization's usage, and they can revoke a key — the one change they can make, so that anyone who notices a leaked key can shut it off immediately. Apart from their own account and security settings, nothing else is theirs to change: they cannot issue keys, manage people, or open the Billing page, which is hidden from them entirely.
Admins can do all of that plus create, regenerate, and edit keys; invite and remove teammates and change their roles; manage billing; and set the organization's security policy.
Two-factor authentication
Enable 2FA from the Security page: under Two-Factor Authentication, click Set Up, scan the QR code with an authenticator app, and confirm the code. Save the backup codes it shows you — they are shown once.
Admins can also turn on Require Two-Factor Authentication for the whole organization, which is
forced on for ITAR organizations. This has a consequence worth knowing before you turn it on: when
an organization requires a second factor, a member who has not enrolled cannot create keys, and
keys they already created are refused by the Engine API with two_factor_required. Enrolling on
the Security page restores them. Enroll the people who hold your keys before requiring it of the
team.
Each key also carries an access grid — read and write in the Core, DFM, and Quoting APIs — chosen
when the key is created, shown beside it on the API Keys page, and editable from the key's menu. A
key used where it has no access is refused with product_mismatch; one that may only read, used
for a write, with read_only_key. See Authentication.
Usage and billing
Progress against your credit limits is on the Usage page, along with recent requests by endpoint and status. Requests appear there once your keys are used. Plan and payment details are on the Billing page.
Managing API keys
Creating, regenerating, and revoking keys is covered in the Quick Start Guide. Only organization admins can create, regenerate, or edit the allowed origins of a key; any member can revoke one.