Developer settings are where you connect Exayard to your own code and to apps other companies build. Open Settings then Developer. Only company admins see it in the Settings menu. A member who opens the page can read it but not change anything.
Apps, API keys, webhooks and logs come with every plan, Free included. Only AI work is charged.
Apps
An app is one of your integrations, like "Acme estimator" or "Nightly sync". Every API key belongs to an app. Apps is the first section on the page. Every member can read it. Only admins make or change apps.
Click New app and fill in its Name, Description, Homepage, Support email and Scopes. Scopes follow a read and write split per resource, like read:projects and write:estimates. Apps can't ask for the admin:org scope. A company can have up to 25 apps.
Each app shows when it was created and its rate limit, like "Up to 60 requests a minute per company and 600 in all". The app's More actions menu holds:
Edit changes the app's details and scopes.
Webhook sets the one address that receives events from every company that installed the app.
Delete app removes the app and revokes all its keys. Every company that installed it loses access.
API keys
An API key lets your own code call the Exayard API. Keys live inside an app, under Keys. A key works in its app's own company, so there is no company ID to pass.
To make one, click New key in the app. Give the key a Name, like "Production". Under Scopes, choose All for every scope the app has, or Specific to pick fewer. Set an optional Expires date if the key is for short-lived work. The key works through the end of that day. Click Create.
Exayard shows the full key once. Copy it then, because it is never shown again. Exayard keeps only a scrambled copy, so a lost key can't be recovered. Make a new one and revoke the old one.
A key starts with exa_live_. A key made in a sandbox starts with exa_test_. After you create it, the key shows its name, a preview like exa_live_...AbCd, and Last used or Never used. A key with an expiry shows Expires and its date, and an expired key shows Expired.
An app can have up to 25 active keys. An expired key still counts until you revoke it. To change keys without a gap, make a second key, move your servers to it, then revoke the first.
Open a key's Key actions menu to Rename it or Revoke it. Revoking can't be undone, and the key stops working within 30 seconds.
If a key turns up in a public place, such as a public code repository, Exayard revokes it, emails your admins, and keeps it in the list marked Found in public, revoked.
When another company has installed your app, the new key dialog also shows Works in. This company is the default. Every company that installed it makes a key your server uses in each of those companies. Each call then names its company in the Exayard-Organization-Id header.
The same keys connect the no-code tools. See Connecting Exayard to Zapier, Connecting Exayard to Make, and Connecting Exayard to n8n. For AI assistants, see Connecting Exa to your AI assistant.
Legacy keys
Keys made before keys lived in apps start with ak_. They keep working, but no new ones can be made. They appear under Legacy keys at the bottom of the page, only while there are any.
Every admin sees every company key there, whoever made it. A key someone else made shows Made by and their name. Each person also sees their own personal keys. Click the trash icon to Revoke a key. It stops working at once.
Sandboxes
A sandbox is a test company linked to yours. Use it to build and test an integration without touching your real projects. Only admins see Sandboxes.
Click New sandbox, give it a Name, and click Create. A company can have up to 5 sandboxes. Open switches you into the sandbox, where the company switcher marks it Sandbox. Make an app and a key there as usual. Its keys start with exa_test_. To go live, make the same app and key in your real company and swap the key in your code.
A sandbox follows your company's plan, and your company pays for its usage. It has no billing of its own and gets no monthly AI usage of its own. Webhooks and integrations work as they do in your real company.
A sandbox doesn't send bid share emails or signed copies to people outside it, and it sends no texts. They show as "Not sent because this company is a sandbox". Invitations to join the sandbox are sent as usual.
Takeoffs and file reads in a sandbox return results copied from our sample project, at no cost. The takeoff, its pages and the takeoff's finished webhook are marked as samples. Estimates, bids, element search and chat answer with samples too, at no cost.
To remove a sandbox, click Delete on its row, then Delete sandbox. The sandbox is closed, its keys stop working, and its data is later erased.
Webhooks
A webhook tells Exayard to notify your server when something happens in your company. Every member can read the list. Only admins add or change webhooks.
Click Create webhook, enter the URL that should receive deliveries, and add an optional Description. Choose which Events to send. Select All to receive every event, new ones included, or Specific to pick from the list. Every event and its contents are listed in the webhook event catalog.
When you create a webhook, Exayard shows its Signing secret once. Copy it then, because it is not shown again.
Open a webhook's More actions menu for the rest:
Edit changes the URL, description and events, and sets its Status to Active or Paused. A paused webhook receives no deliveries. The dialog also has Rotate secret. The old secret stops working at once, so update your server first.
Send test event sends one event of the Event type you choose. The dialog waits for your server's answer and shows the result and the response code. A test event carries
"test": true.Deliveries lists the last 25 deliveries with their event, status, response code and number of attempts. A delivery is Pending, Retrying, Delivered or Failed. Admins can click Resend to send a delivery again.
Delete webhook ends all deliveries to that URL.
A test event and a resend are sent once and never retried.
Securing webhook deliveries
Every delivery carries an Exayard-Signature header in the form t=<unix>,v1=<digest>. Exayard builds the signature by joining the timestamp and the request body, then signing them with HMAC-SHA256 using your webhook's secret.
Each delivery also carries Exayard-Event-Id, Exayard-Event-Type, and Exayard-Organization-Id headers. The JSON body has an organizationId field that names the company the event came from. The header carries the same id, so you can route a delivery before you read the body. The signature covers the whole body, organizationId included.
Because every delivery names its company, one receiver address can serve many companies. Register the same URL in each company and route each delivery by organizationId. Each webhook has its own secret, so pick the secret by Exayard-Organization-Id before you verify.
To verify a delivery, recompute the signature with your secret, confirm the timestamp is within five minutes of now, and compare the digests.
A failed delivery is tried up to 10 times in all, over about 80 hours, with longer waits between tries. Every try sends the same body and the same event ID. A redirect counts as a failure.
Let other companies install your app
Your app works in your own company as soon as you make it. Each app also has a Let other companies install this app part. It shows whether the app is Reviewed, Review requested or Not reviewed, its Sign-in addresses, its Client ID, and how many companies can install it.
Admins open the Install actions menu for these:
Edit sign-in addresses sets the addresses Exayard returns people to when your app signs them in with their Exayard account. Enter one address per line, up to 10. Each must start with
https://, orhttp://localhostwhile you test. The first time you save sign-in addresses, Exayard shows the app's Client secret once.Copy install link copies a link you can send to any company. It opens the install dialog for that company's admin.
Ask for review sends the app to Exayard support for review.
A new app can be installed in up to 25 companies besides your own, and it doesn't appear in Find apps. Companies under Accounts for your customers don't count toward that limit. Once approved, the app shows Reviewed and the install limit is lifted. Use Show in Find apps to list it in every company's directory, or Hide from Find apps to take it off. A Suspended app can't call Exayard until support lifts the suspension, and its installs are kept.
When you remove scopes from an app, every install loses them at once. When you add scopes, each company keeps its current access until one of its admins approves the new scopes.
App webhook
Open the app's More actions menu and click Webhook. Enter the URL and click Create, then copy the Signing secret, which Exayard shows only once. Each company that installed the app sends the events its granted scopes cover. Your app also receives app.installed, app.scopes_approved and app.uninstalled when a company installs it, approves wider access or removes it. Deliveries name their company and are signed the same way as other webhooks.
The same dialog lets you Pause and Resume deliveries, Rotate secret, and Delete webhook.
Connected apps
Connected apps lists the apps installed in your company. Every member can see it. Only admins install, remove or approve.
Each row shows the app's name, whether it is Reviewed, the company that built it, who installed it and when, and the scopes it was granted.
Installing an app
Open the app's install link, or click Install next to it in Find apps. The dialog shows who built the app, whether it is reviewed, and the scopes it asks for. Then choose:
Company: any company where you are an admin. A company that already has the app is marked (installed). Installing again saves your new choices.
Projects: All projects, or Only these projects and tick the ones the app may reach, up to 500. The app can't reach any other project in the company.
Monthly AI limit: the most the app's AI work may cost your company each billing month, in your billing currency. Leave it empty for No limit.
Click Install. If the app signs you in, Exayard then takes you on to finish signing in to the app. If you are a member but not an admin, the dialog tells you which company's admin can install it. Click Copy link to send it to them.
To change the projects later, open the install link again and install with the new choice.
Approving more access
When an app asks for more scopes, its row shows Asks for more access with the new scopes. An admin clicks Approve to grant them. Until then, the app keeps the access it had.
Removing an app
Open the app's More actions menu, click Remove, and confirm. The app loses access to your company at once and its webhooks stop. AI work it had already started still finishes.
Find apps
Find apps appears inside Connected apps. It lists reviewed apps their builders chose to list. An app your company already has shows Installed. Click Install on any other app to open the install dialog.
Your personal connections
Your personal connections lists the AI tools and other apps you connected to your own Exayard account, like ChatGPT or Claude. It appears at the top of Connected apps, and only you see your own. A personal connection acts as you, so it can reach whatever you can.
Each connection shows when it was first and last used, and the companies it was used in. To stop one, open its More actions menu, click Remove, and confirm. Its next call is refused. The connection stays in the list marked Removed, and Allow again lets it back in. To connect a new tool, see Connecting Exa to your AI assistant.
Accounts for your customers
Your app can create Exayard companies through the API for customers who use Exayard only through your product. Your company owns these companies and pays for the AI work done in them. They have no members of their own, and your apps are installed in them automatically.
Accounts for your customers lists them for admins, with each company's Name and the date it was Created. Click Release and confirm to close one. Every app in it loses access.
Get started
The Quick start card holds a ready-made prompt for an AI editor like Claude or Cursor. Click Copy prompt and paste it into your editor. The prompt includes the API base URL, the authentication format, the scopes, and the webhook signing scheme, so the AI can build a working integration and ask you for the details it needs. Only admins see this card, because it needs an API key.
The Documentation card links to the full developer docs with Open docs, and to the OpenAPI spec, which describes every route and schema. Admins also see Connect to Claude or Cursor, which opens the setup for connecting AI assistants to Exayard.
Logs
Logs shows the requests made to the API, newest first. Each row shows the Method, Path, Status, Time and Latency. Click Load more at the bottom to see older requests.
Admins see every request. Members see only the requests that didn't come through an app.
Admins can filter by App, and then by one of that app's keys. Anyone can type an End user to see only that customer's requests. An end user is your own ID for one of your customers. Your code sends it with each request in the Exayard-End-User header. Never use an email address as the ID.
Select a row to see its full detail, including the Request ID, the app and end user, and the Request body and Response body. Use the logs to confirm a call worked or to find out why an integration fails.
Spending by key and end user
Admins see what each app spent this month under Spending by app in Settings then Usage. Your own apps are listed there too. Under each app, By key shows what each key spent, and Top end users shows the five end users who spent the most. Spending not tied to one of the app's keys shows as Other.
Monthly AI limit
An app's monthly AI limit is the most its AI work may cost your company each billing month. To set it, open the app's More actions menu under Spending by app and click Set monthly AI limit. Enter an amount in your billing currency and click Save. Save an empty field to remove the limit.
When the app reaches its limit, its AI work is refused for the rest of the billing month, even while your company still has AI usage left. Your company's own limits still apply. AI work people start themselves is never counted against an app's limit.
