Creavax

Creavax product guide

Creavax Account and Security: protect access, tokens, teams and permanent account actions

Account security is mostly about controlling credentials and irreversible actions: keep passwords and tokens private, verify team leadership before deleting access and read destructive confirmations before proceeding.

Account & Security workspace
Creavax account settings with profile, API token and account security controls
ACCOUNT · TOKEN · TEAM · DELETE

Protect credentials and slow down before irreversible actions

Keep API tokens private, maintain a recognizable account, understand team leadership responsibilities and treat permanent account deletion as a final operation.

IdentityProfile access
APIPrivate token
DeletePassword confirmed

Quick start

Use the workspace in the right order

Follow this order for a clean first pass. You can return to the deeper sections when a permission, billing choice or destructive action needs more context.

01

Review account identity

Keep the profile recognizable and make sure the account email and username match the identity you expect to use.

02

Audit developer access

Create a personal API token only when an integration needs one and rotate it when exposure is suspected.

03

Review team responsibilities

Before deleting or abandoning an account, check whether you lead teams that require ownership transfer or deletion.

04

Read destructive confirmations

Treat account deletion and other irreversible actions as final and verify the consequences before entering the password confirmation.

Core capabilities

What you can do in this workspace

Use these capabilities to understand what belongs here, what connects to another workspace and which actions change public, billing or account state.

01

Profile identity

Keep name, username, avatar and profile information current so collaborators can recognize the account.

02

Developer token control

Create or rotate a personal Developer API token without exposing it in frontend applications or public text.

03

Team ownership safety

Resolve leadership responsibilities before removing access to a team-controlled workspace.

04

Protected account deletion

Use a password-confirmed destructive flow that warns about credits, public content, API access and team leadership.

Detailed workflow

Make each important action with context

These sections explain the decisions that matter most before you organize assets, spend credits, publish content, collaborate or change account access.

01

Treat tokens like passwords

A Developer API token can authorize server-side activity and should never be pasted into a prompt, support request, screenshot, public repository or frontend bundle. Store it in a protected server environment variable or secret manager.

If a token may have been exposed, rotate it instead of waiting to see whether it is abused. Update the integration with the replacement secret and remove the old value from logs or configuration where possible.

  • Never place API secrets in client-visible JavaScript.
  • Rotate exposed credentials promptly.
  • Limit screenshots of Settings and API pages when a secret is visible.
02

Prepare before permanent account deletion

Permanent deletion affects more than the visible profile. Review remaining credits, public content, API access and team leadership before confirming the action.

If the account leads a team, transfer ownership or resolve that workspace first. Do not use deletion as a substitute for signing out or temporarily stopping work.

  • Download anything you still need before deletion.
  • Transfer team ownership when required.
  • Use sign-out when you only want to end the current session.

Best practices

Work faster without losing control

  • Use a password manager for account credentials.
  • Keep API tokens server-side and rotate suspected exposures.
  • Review team ownership before any permanent account action.

Frequently asked

Questions about Account & Security

Quick answers to the questions that most often come up before using this workspace.

Should I send my API token to Creavax Support for troubleshooting?

No. Do not send secrets through Contact, prompts or screenshots. Describe the issue without sharing the token value.

What should I do if an API token is exposed?

Rotate the token, replace it in the trusted server integration and remove the exposed value from public code, logs or screenshots where possible.

Is deleting my account the same as signing out?

No. Sign-out ends the current session. Account deletion is presented as permanent and requires password confirmation after showing its consequences.

Continue learning

Related Creavax guides

Continue with the next workspace only when it supports the same task, billing context or publishing flow.

Ready to use the real workspace?

Put the guide into practice

Open Account & Security, complete one small real task and return to this page when you need the detailed workflow.