Connectly Rootly
Create a Global API Key for Trustle to synchronize on-call schedules with JIT approvals
Overview
This guide will help you configure a Rootly Global API key so Trustle can securely discover your on-call configuration (users, teams, schedules, escalation policies, services, and roles) and grant or revoke just-in-time on-call access.
What you'll need
- A Rootly organization admin who can manage API Keys
- Access to the Trustle Connections page
Note: Trustle cannot create Rootly users. People must already exist in Rootly (matched by email) before access can be granted.
Step 1: Log in to Rootly
Log in to your Rootly organization at https://rootly.com as a user who can manage organization settings.
Step 2: Navigate to API Keys
- Open Organization Settings
- Select API Keys
Step 3: Create a Global API Key
- Click to create a new API key
- Enter a description (for example, "Trustle Integration")
- Choose the Global scope (not Team or Personal)
- Assign roles to the key. Prefer custom, minimally scoped roles:
- Custom On-Call role: read on all on-call resources; create/update/delete on schedules, schedule overrides, escalation policies, and groups (teams); update on on-call roles and users
- Custom Incident Response role: read plus update on groups, services, roles, and users
- Owner or Admin roles also work, but grant more than Trustle needs
- Note the key's expiration date — Rootly keys expire explicitly
Step 4: Copy the API Key
Important: Copy the API key immediately — it is only displayed once.
The key looks like: rootly_0123456789abcdef…
Step 5: Store Credentials in Trustle
- Go to Trustle's Connections page
- Under SaaS Applications, find Rootly and click Connect
- Fill out the connection form:
- Connection Name: Enter a descriptive name for this connection
- API Token: Paste the Rootly Global API key you copied
- Click Test Connection to verify the credentials work
- Click Save Connection
Security Notes
- Use a Global key with custom minimal roles when possible — do not use a Personal API key
- Rotate the key before it expires
- Store the token only in Trustle; do not share it in chat or commit it to version control
