Skip to main content
Intercom uses a long-lived API key. Authsome stores the key encrypted in the local vault, injects it at request time through the proxy, and keeps it out of shell history, process listings, and environment dumps.

At a glance

Get a key

Create an API key in the Intercom dashboard at https://app.intercom.com/a/developer-hub. Intercom access tokens live under your workspace’s developer hub. Replace _ placeholders in the URL with your real workspace.

Log in

A local browser form opens at http://127.0.0.1:7998. Paste the key into the masked input and submit. On a headless machine without a graphical session, authsome falls back to masked terminal input via getpass. The browser bridge is skipped automatically when no display is available. Verify:

Use the key

Run the agent under the proxy (recommended).
Under the proxy, authsome sets INTERCOM_API_KEY=authsome-proxy-managed in the child’s environment and injects the real key into outbound requests to api.intercom.io. The child process never sees the actual value.

Multiple keys

Pass --connection <name> on login and on every read command to keep two or more accounts on the same provider side by side. See Multiple connections per provider for the full pattern.

Rotate or remove the key

API-key providers have no revocation endpoint, so revoke and remove are equivalent for Intercom.

Override the bundled definition

What’s next

Run agents with the proxy

Keep the key out of the agent’s environment entirely.

Multiple connections per provider

Keep two or more keys on the same provider side by side.

API-key providers

All bundled API-key providers.