We are excited to announce significant updates to the customer panel and API system. These changes enhance account security, provide you with greater control over access, and simplify the management of your team and integrations.
Intelligent device verification system
Our first major update introduces a device verification system during the login process. This feature intelligently reviews login attempts to your account and asks you to confirm the request if it detects a different device. For accounts without two-factor authentication (2FA), this protection is automatically enabled.
We strongly recommend enabling 2FA for maximum account security.
You can enable 2FA by going to the "Account" menu in the sidebar, navigating to the "Profile" tab, and clicking on "Enable" in the 2FA section.
If you cannot use a mobile device, password managers like Bitwarden or 1Password (and others) can securely store your one-time passwords for convenient logins.
If you need to share account access with your team, please use our subaccount system. Subaccounts let you add team members to your company account while maintaining a clear overview of each user's activity in the audit log. If a subaccount is ever compromised, you can instantly disable its access with one click.
To create subaccounts, click on the "Company" menu in the sidebar, then go to the "Users" tab. From there, you can create new accounts or invite existing Priority Prospect users. This is especially useful when collaborating with a partner company to manage your account.
New API authentication
Previously, API access required your account credentials. With the new login protection, we have transitioned to API keys.
You can now generate API keys directly in the panel. Simply click on the "Company" menu, then navigate to the "API Keys" tab (available only to company owners).
Click on the "Create API Key" button to open the setup window, where you can configure detailed permissions for each API user. You can also limit access to specific domain groups, IP groups, hosting accounts, and software presets.
For security, every API key must include at least one allowed IP address. While unrestricted access is not permitted, you can add as many IP addresses as needed.
Like subaccounts, all API actions are logged in the audit log for complete transparency.
To send API requests, include the following headers:
Company: [company id]
Authorization: Bearer [API key]
Please note: API requests are only supported over HTTPS.
Other improvements
In addition to these updates, we have made several backend enhancements to increase system security and optimize performance, ensuring our services remain fast and reliable.
We hope you find these updates valuable. If you have any feedback, questions, or suggestions, we would love to hear from you.
Best regards,
The Priority Prospect Team