Organizations & Teams
apistash works entirely on your own personal account, but it also supports collaboration through organizations and teams.
Organizations
An organization is a shared workspace with its own members, roles, API keys, OAuth clients, plan, and — most importantly — its own catalogue of prompts, resources, custom tools, and agent definitions. Members work from the same catalogue instead of duplicating content across personal accounts.
Teams
A team is a sub-group inside an organization. Teams scope content and access: a team can own prompts, resources, custom tools, and agent definitions, and a credential's team bindings determine which team-scoped content it can reach.
Ownership spaces
Every customer prompt, resource, custom tool, and agent definition has exactly one owner. There are four ownership spaces:
| Space | What it contains |
|---|---|
| Personal | Items you own outside any organization |
| Personal-in-org | Items you own within an organization (me/ namespace) |
| Team | Items owned by one team ({team}/ namespace) |
| Organization | Items owned by the organization in its unprefixed catalogue |
Prompts, resources, and custom tools can be promoted into a wider ownership space. The ownership of an agent definition is fixed when it is created.
What a credential sees
For each surface a credential can use, its context determines which ownership spaces it draws from:
- A personal credential draws from your personal-space items.
- An organization credential draws from the organization's catalogue, the team-owned items of the teams it is bound to, and — if it acts on behalf of a user — that user's personal-in-org items.
- A credential with no team bindings draws no team-owned items; it can still draw from organization-wide items and, when it acts on behalf of a user, that user's personal-in-org items.
Platform prompts are separate from these customer ownership spaces and require effective Prompts capability, their platform allowlist and additive team/org-wide admission; see Platform prompts.
What a credential actually lists and calls is narrowed further by the access model, starting with whether it was granted that surface at all. Organizations, teams, members, and roles are managed in the dashboard.