Connect Linear safely (API key and team scope)
Linear works best when your agent has focused access. Avoid owner-level keys and scope to the specific teams where automation is required.
1
Use dedicated service user
- Create a dedicated Linear user for your agent.
- Add it only to the teams it should access.
- Avoid personal owner accounts for integrations.
2
Manage API keys as secrets
Generate a personal API key from the dedicated account, store it in secret management, and never paste it in public channels or issue comments.
3
Start read-only, then expand
- Validate issue search and summaries first.
- Add create/update workflows only after approval.
- Track what actions the bot performs in logs.