Currently every user within Freshdesk has access to an API key, meaning that any user could: extract data, bulk update tickets, etc. from outside of the application. This is a security risk.
Admins should be able to switch off a user’s ability to have an accessible API key to prevent this


