IDs returned by the public API are opaque strings. Store them as strings and pass them back exactly as returned. Do not infer database UUIDs or construct IDs yourself.
Every API key is associated with a workspace. Authenticated public API reads and writes are scoped to that workspace. Keep workspace-specific IDs separate in multi-tenant integrations.
Follow each endpoint schema for nullability and omission. Empty collections are valid results. Do not treat an absent optional field as an empty string unless the endpoint says so.
Delete, launch, stop, publish, rotate-secret, test-call, and outbound-message operations may have irreversible or external side effects. Require an explicit user action and log the resource ID, operation, and outcome.