Frequently asked questions
Straight answers about how Tempkey works, what it costs, and what happens when a grant expires.
What does Tempkey actually do?
Tempkey grants a contractor access to your work tools with a built-in expiry date, then automatically revokes that access when it ends and confirms the revoke actually took effect.
Is Tempkey for contractors only, or employees too?
Tempkey is purpose-built for time-boxed access — contractors, freelancers, agency staff, and short-term hires. It isn’t designed to replace full employee lifecycle/HRIS systems.
How does revoke verification work?
When a grant expires or is revoked manually, Tempkey calls the provider’s API to remove access, then reads the provider’s state back to confirm the removal actually succeeded before marking the grant closed.
What happens if a revoke fails?
A failed or partial revoke is flagged clearly in the dashboard and audit log rather than silently marked complete, so the workspace owner knows exactly what still needs manual attention.
Which tools does Tempkey connect to?
GitHub, GitLab, Figma, Dropbox, Asana, Slack, Google Workspace, Microsoft 365, Zoom, and AWS IAM are natively enforced. Notion, and Trello are supported as limited-native with explicit capability labeling. Zapier and Make bridges cover additional tools as best-effort webhook automations.
Do I need a credit card to start?
No. The Free plan needs only a work email — no credit card, ever, unless and until you choose to upgrade.
What counts as an "active contractor grant"?
One contractor’s live, non-revoked access to your tools. Ten active grants means ten contractors with live access at the same time — revoke one and that slot frees up immediately.
What happens when I reach my plan’s grant limit?
New grants are refused with a clear error (HTTP 402 on the API) until you revoke an existing grant or upgrade. Grants you already have keep running, keep sending reminders, and keep revoking themselves on schedule — nothing already granted is interrupted.
How are my provider credentials stored?
Admin tokens are write-only in the browser: submitted once, encrypted at rest by the backend, and never displayed or returned to the UI again.
Is there a trial of Team or Business?
Not a time-limited trial — the Free plan itself has no time limit, so you can run the full grant-to-revoke loop for as long as you need before upgrading. Downgrading later keeps your audit history exportable.
Can I change or cancel my plan?
Yes. Plans are month to month with no lock-in. Downgrading or cancelling takes effect at the end of the current billing cycle, and your audit history stays exportable.
How long is audit history kept?
Free keeps 30 days, Team keeps 90 days, and Business keeps 180 days — all exportable as CSV or PDF at any time, on every plan.
Glossary
A few terms used throughout the site, defined in plain language.
What does "grant" mean?
A grant is one contractor’s access to your tools, with an end date. Ten active grants means ten contractors with live access at the same time — revoke one and that slot frees up immediately.
What is a "provider" in Tempkey?
The tool you’re granting access to — Slack, GitHub, Google Workspace, and so on. Tempkey calls each provider’s own API to add and remove access.
What does "revoke" mean?
Removing a contractor’s access. Tempkey revokes automatically when a grant expires, or you can revoke manually at any time — either way, it then confirms with the provider that access is actually gone.
What’s a "workspace"?
Your team’s account in Tempkey — the contractors, grants, connected providers, and audit log for one organization.
What are "scopes"?
The specific permissions an admin token grants Tempkey on a provider — for example, the ability to remove a user, but not to read their messages. Each integration screen lists exactly what’s requested before you connect it.