Connectly Rootly

Create a Global API Key for Trustle to synchronize on-call schedules with JIT approvals

Overview

This guide will help you configure a Rootly Global API key so Trustle can securely discover your on-call configuration (users, teams, schedules, escalation policies, services, and roles) and grant or revoke just-in-time on-call access.

What you'll need

  • A Rootly organization admin who can manage API Keys
  • Access to the Trustle Connections page

Note: Trustle cannot create Rootly users. People must already exist in Rootly (matched by email) before access can be granted.

Step 1: Log in to Rootly

Log in to your Rootly organization at https://rootly.com as a user who can manage organization settings.

Step 2: Navigate to API Keys

  1. Open Organization Settings
  2. Select API Keys

Step 3: Create a Global API Key

  1. Click to create a new API key
  2. Enter a description (for example, "Trustle Integration")
  3. Choose the Global scope (not Team or Personal)
  4. Assign roles to the key. Prefer custom, minimally scoped roles:
    • Custom On-Call role: read on all on-call resources; create/update/delete on schedules, schedule overrides, escalation policies, and groups (teams); update on on-call roles and users
    • Custom Incident Response role: read plus update on groups, services, roles, and users
  5. Owner or Admin roles also work, but grant more than Trustle needs
  6. Note the key's expiration date — Rootly keys expire explicitly

Step 4: Copy the API Key

Important: Copy the API key immediately — it is only displayed once.

The key looks like: rootly_0123456789abcdef…

Step 5: Store Credentials in Trustle

  1. Go to Trustle's Connections page
  2. Under SaaS Applications, find Rootly and click Connect
  3. Fill out the connection form:
    1. Connection Name: Enter a descriptive name for this connection
    2. API Token: Paste the Rootly Global API key you copied
  4. Click Test Connection to verify the credentials work
  5. Click Save Connection

Security Notes

  • Use a Global key with custom minimal roles when possible — do not use a Personal API key
  • Rotate the key before it expires
  • Store the token only in Trustle; do not share it in chat or commit it to version control

Matthew Hathaway