Admin
Developer Access: API Keys, Agents and Activity
Developers is where an admin manages programmatic access to Forge. It has four tabs: Keys, Agents, Approvals, and Usage & Logs. The older Checkout API address now redirects here, keeping its query parameters.
Keys
Use Keys to issue API keys for the Checkout API, which lets you put Forge event registration on an external website. The tab includes a short "Get started with Checkout API" guide and shows "Your API Endpoint", the base URL for SDK and REST calls.
- Click Create Key and enter a Key Name.
- Choose a Type: Publishable or Secret, and a Mode: Live Mode or Test Mode.
- Optionally set Allowed Origins and an Event Scope, and pick a Product and Scopes. Leaving both scope options unchecked gives unrestricted access.
- Click Create Key, then copy the key straight away. It is shown only once.
- A publishable key is safe to use in browser code. Set Allowed Origins to your website domain so only your pages can use it.
- A secret key is for server-to-server calls only. Never expose it in a browser.
- Rotate revokes a key and issues a new one. Revoke immediately rejects all requests that use the key and cannot be undone.
The Embed Snippet section generates a script tag once you select an event and a publishable key. It also has Appearance options for Theme (Auto, Light, Dark) and Locale. Copy the snippet into your webpage.
If direct-to-Salesforce checkout is used, the Salesforce write identity control lets you Connect, Reconnect or Disconnect a dedicated Salesforce user. Disconnecting stops direct-to-Salesforce checkout until a new identity is connected.
Agents
Agents manages AI assistants connected to Forge. Under "Generate a bearer token", click Generate token for assistants whose connector does not support OAuth and paste it into the connector auth field. The token is shown only once. "Connected agents" lists each agent with its connection and expiry dates, and Revoke disconnects an agent immediately; it can reconnect later.
- Agent write access can be switched between "Writes paused" and "Writes allowed". While paused, no connected agent can create, update or delete records, but reads still work. It takes effect immediately, including for agents already connected.
- Salesforce write identity: connect a dedicated Salesforce user so agent-originated writes have a named identity you can disconnect. Disconnecting stops agent writes until a new identity is connected.
Approvals
Approvals shows "No pending approvals". The tab is not yet active: every agent write today runs immediately, subject to the write-access setting on the Agents tab.
Usage & Logs
"Recent activity" lists agent and API tool calls with Tool / Action, Status (Success or Error) and Date. Read-only calls are only logged when detailed auditing is turned on, so the list is weighted toward writes.
Developers is available to org admins only.