Skip to main content
Workspaces give teams a shared operational home without changing who technically owns a project. They are designed for agencies, businesses, and internal teams that need to manage UPG capacity, billing, team access, and approved project operations.

Personal Workspace

Every account has one Personal Workspace. New projects belong here by default.

Business Workspace

A shared Workspace for a team, agency, or business to manage approved work.

Two layers of project ownership

Every project has a technical owner and a management Workspace. These are intentionally different responsibilities. The technical owner never loses access merely because a project is connected to a Business Workspace.

How a connected project works

Project linking uses a time-limited Workspace Connect Key. The technical owner chooses exactly what the Business Workspace may manage before the key is redeemed.
1

Create a Connect Key

The technical owner creates a Connect Key.
2

Choose permissions

The owner chooses delegated project permissions.
3

Redeem the key

The Business Workspace redeems the key.
4

Project connected

The project is successfully connected to that Workspace.
5

Managed access

Workspace members act only within role and delegated permission limits.
For example, a client can allow an agency to configure UPG gateways while refusing permission to rotate project API credentials.
Workspace role permissions and project delegation are both required. A team member needs permission from their Workspace role, and the connected project must also have delegated that category to the Workspace.

Team roles and invitations

Workspace Owners can invite members, assign default or custom roles, and apply granular permissions. An invitation creates a pending invitation first; membership becomes active only when the invited AvraAPI account accepts it. The Workspace owner bypasses normal Workspace permission checks. Other members receive only the permissions assigned by their role.

UPG capacity and connected projects

UPG plans belong to the Workspace, while encrypted gateway configurations belong to the individual project. A project must have an active Workspace UPG slot before it can create new payment checkout sessions. This separation means an agency can manage its Workspace capacity without ever receiving a customer’s gateway secret.

Connect projects

Learn about Connect Keys, delegation, and safe project exit.

Roles & permissions

Understand the layered authorization model.

Plans & capacity

Learn how UPG entitlements and project slots work.
Last modified on October 1, 2026