# Settings

> The seven tabs of the account Settings screen: sign-in security and SSO, API keys, white-label branding, provider and vendor credentials, infrastructure endpoints and storage, telephony tools, and the audio library.

**Settings** is the account-wide configuration screen. It holds what applies
to the whole organization, not to one product: how people sign in, which
credentials TeleQuick uses to reach other services, and what every console
looks like.

Per-product configuration does not live here. A trunk belongs to Voice, an app
key belongs to Realtime, and each console keeps its own. Settings holds only
what crosses products.

The screen has seven tabs.

| Tab | What it holds |
| --- | --- |
| Account & Security | Sign-in security, password, connected accounts, SSO |
| API Keys | The organization admin token for server-to-server calls |
| Branding | White-label appearance for every console |
| Credentials | Keys TeleQuick uses to reach model and vendor APIs |
| Infrastructure | Service endpoints and their reachability, plus storage use |
| Tools | Telephony tools an agent can call |
| Audio | The shared audio library |

## Account & Security

Four surfaces, all about how a person proves who they are.

- **Security** — multi-factor authentication for your own account.
- **Password** — change it. This is the only place the portal writes one.
- **Connected accounts** — the social identities linked to your account, if
  your deployment enables them.
- **SSO** — single sign-on for the organization. Once SSO is enforced, members
  sign in through your identity provider instead of a password.

> **NOTE:**
> MFA and password apply to YOU. SSO applies to the ORGANIZATION. Changing SSO
>   changes how every member signs in, so it is an administrator action.

## API Keys

The organization **admin token**. It authenticates server-to-server calls
against the administration API, so it acts for the organization rather than
for a person.

It has its own tab for one reason: when you need to rotate the credential that
a script uses, you should not have to look for it inside a screen about your
own password.

> **WARNING:**
> The admin token is shown once. Rotating it invalidates the previous value
>   immediately — deploy the new one before you rotate, or scheduled jobs fail on
>   their next run.

For agent-scoped and MCP credentials, see [MCP](/platform/mcp). Those are
narrower by design and are the right choice for anything that does not need
full administration rights.

## Branding

White-label appearance: the name, logo and colours every console renders.

Branding is deployment-wide. It is the only setting on this screen that changes
what EVERY console shows — the portal, the voice console, and each modality
SPA. A change here is visible to every member of the organization at once.

## Credentials

Two kinds, and the difference matters:

- **Provider credentials** — the organization-wide default keys TeleQuick
  uses to reach a model provider on your behalf. A voice agent with no key of
  its own falls back to these.
- **Vendor credentials** — keys for a third-party platform TeleQuick bridges
  to.

Both are stored sealed and are never returned to the browser after you save
them. The screen shows that a credential is set, not what it is.

> **NOTE:**
> A voice agent can carry its own provider key on its Keys tab. That override
>   wins. Use the organization default for the common case and the per-agent key
>   when one agent must bill to a different account.

## Infrastructure

Two things: where this deployment's services are, and how much storage the
organization uses.

The endpoint table probes each service from your browser and shows whether it
answers:

| Service | Purpose |
| --- | --- |
| Supabase | Portal database and authentication |
| TeleQuick API | The API gateway to the telemetry services |
| Admin QUIC | Binary administration RPC over QUIC (optional) |

Only services the browser can reach directly are probed. Everything else runs
through the API gateway, which holds the real credentials — so a service
missing from this table is not a service that is missing.

A red row here is the fastest way to tell a misconfigured deployment from a
broken feature.

## Tools

Telephony tools a voice agent can call during a conversation — transfer a
call, look a number up, and so on. Configure them once here and any agent in
the organization may use them.

The agent still decides whether to call a tool. Configuring one makes it
available; it does not make it mandatory. See
[Tool calling](/modalities/voice/runtime/tool-calling).

## Audio

The shared audio library: hold music, prompts and any other clip an agent or a
queue plays. Uploading a clip here makes it selectable everywhere it can be
played.

## Where the other settings are

| Looking for | It is here |
| --- | --- |
| Spend and usage | [Billing](/platform/billing) |
| Who can reach which product | Access management, in the portal |
| Trunks, numbers, dispatch rules | The Voice console |
| Application keys | Each modality's own console |
| Voices | The Agents screen — a voice is an agent asset, not an account setting |
