Skip to content
ZeroCaptcha

Teams and roles

An account can have several people, each with their own email, password and second factors, all sharing the account’s keys, tasks and balance. Whoever signs up owns the account; invite the rest from the dashboard’s Team page.

Owner Member
Use the account’s API keys, and see the keys page Yes Yes
See tasks, usage and the balance Yes Yes
Create, rotate, restrict and revoke keys; set spend caps Yes No
Top up, see receipts, set billing details and the low-balance email Yes No
See and rotate the callback signing secret Yes No
Invite people, change roles, remove people, read the activity log Yes No
Leave the team Yes Yes

A member who tries an owner’s action is refused with role_required (HTTP 403). API keys are the account’s, not a person’s: removing someone does not revoke a key they created or used. Rotate the keys they had (see API keys) if that matters to you.

  1. On Team, enter their email address and choose a role.
  2. We email them a link. It works once, for 7 days, and only while the address has no ZeroCaptcha account: an address belongs to one account.
  3. They open it, choose a password, and are signed in. The link proves their address, so it counts as verified.

Inviting the same address again replaces the open invitation, and its old link stops working. An account may have 20 invitations open at once. Revoke one from the Team page and its link stops working at once.

Owners change a person’s role or remove them from the Team page; anyone may leave. An account always keeps an owner: the last owner can neither leave, be removed, nor become a member, so promote someone first. Two owners changing each other’s roles at the same moment cannot both succeed.

Removing someone deletes their user: they are signed out everywhere, and their password, passkeys and second factors go with it. To bring them back, invite them again.

Every change to the team, and every rotation of the callback secret, is recorded: who did what, to whom, and when. Owners read it on the Team page.