# Account settings

These settings live in the menu under your name in the header. They apply to you alone
and affect nobody else in the workspace.

## Preferences

| | |
|---|---|
| **Theme** | Light or Dark. |
| **Language** | The app's own labels. It does not change what language agents answer in. |
| **Default agent** | Which agent new chats start with. **Use Organization Default** follows the workspace's choice. |
| **Default Image Edit Agent** | Which agent handles **Edit with AI** on a file. |

## Profile and sign-in activity

**Account Settings** holds your name, profile picture and password.

**Security Activity** lists sign-ins, password changes and second-factor activity on your
account, as reported by the identity provider: when, from which approximate location, and
on which browser or device. Times reflect when authentication was processed and can
include automatic session renewals, so seeing more entries than you remember signing in
is normal.

Check it if you suspect a problem. An unfamiliar location warrants a password change.

## API keys

**Account Settings → API Keys.** A key lets your own software call the platform API as
you.

| | |
|---|---|
| **Name** | What it is for. |
| **Expiration** | Defaults to 90 days. |
| **Permissions** | **Full access**, **Read-only**, or **Custom**. |
| **IP allowlist** | Optional. One address or CIDR range per line. |

Four rules to know before you create one:

**A key can never do more than your account can.** It starts from your permissions and
narrows from there. If your roles change, the key's reach changes with them.

**Read-only means read-only**: list, view and search, never create, change or delete. It
is the right choice for reporting or for syncing data outward.

**The key is shown once.** Copy it when it is created, because it cannot be retrieved
afterward. Treat it like a password.

**Revoking is permanent.** The key is disabled and every request made with it is
rejected.

<Callout type="caution">
	Prefer a narrow key with an expiry over a full-access key without one. A read-only key
	locked to your server's IP address carries far less risk if it leaks than a key that
	can do everything you can.
</Callout>

Building against the API is documented separately. See the [developer
documentation](/developers), and [authentication](/authentication) for how to use the
key you just created.

## Memory

What the AI remembers about you, and the controls to pause or delete any of it. See
[memory](/guide/ai/memory).

## Notifications

The bell in the header. New leads from [chat widgets](/guide/automation/chat-widgets),
finished [calls](/guide/automation/voice-agents), and completed jobs. **Mark all read**
clears the badge.
