Token access you control
Hosted CrystalSlate uses a verified CrystalSlate account and a Smartsheet personal API token that you enter in Settings. The token carries exactly the permissions of your Smartsheet account, nothing broader.
Security
CrystalSlate is built around controlled access, role-aware behavior, deliberate write actions, and careful support practices.
Hosted CrystalSlate uses a verified CrystalSlate account and a Smartsheet personal API token that you enter in Settings. The token carries exactly the permissions of your Smartsheet account, nothing broader.
The product emphasizes read-only review, exports, and owner confirmation before high-impact write workflows.
CrystalSlate-initiated writes are designed to leave an activity record that can support operational review.
CrystalSlate's launch mode uses an email-and-password account with email verification. After signing in, you enter your own Smartsheet personal API token in Settings for the workspace session. There is no OAuth-style scoped authorization today; OAuth remains a future direction and should not be treated as available until explicitly announced.
app.crystalslate.com.CrystalSlate is a Smartsheet companion workspace. It may display Smartsheet metadata and review results needed for the workflow you run. Avoid using production-sensitive examples in screenshots unless they are redacted.
Email security reports to hello@crystalslate.com with “Security report” in the subject. Include the affected page or workflow, reproduction steps, browser, approximate time, and impact. Do not include secrets or exploit customer data to prove impact.