An API key is not just a setting. It is access.
If a tool uses your Fathom API key to export meeting data, treat that key with the same care you would give other sensitive work credentials.
What a Fathom API Key Can Enable
Fathom's public API is designed to bring meeting summaries, transcripts, and action items into other workflows.
Depending on the endpoint and access available to the key, meeting export workflows may involve:
- Meeting metadata.
- Recording IDs.
- Meeting titles.
- Participants.
- Summaries.
- Transcripts.
- Highlights.
- Action items.
That data can include customer names, business context, support issues, implementation details, and internal commitments.
Safe API Key Practices
Use these rules:
- Create the key only in the official Fathom account flow.
- Paste it only into tools you trust.
- Do not email the key.
- Do not paste the key into tickets or chat.
- Do not include it in screenshots.
- Do not share it across a whole team if individual access is expected.
- Rotate it if you think it was exposed.
- Remove it from tools you no longer use.
If a workflow does not need transcript access, avoid exporting transcripts by default.
Local-First Export Workflows
Koda Sidecar's Fathom app is designed around a direct user-controlled path:
- The user provides their own Fathom API key.
- API requests go directly to Fathom.
- Export files are generated locally in Chrome.
- Koda Sidecar does not use meeting content to train AI models.
- Email drafts are reviewed by the user before sending.
That design reduces unnecessary data movement, but users still need to protect the API key and exported files.
What to Review Before Exporting
Before exporting meeting data, decide:
- Which meetings need export.
- Whether transcript detail is necessary.
- Whether summaries are enough.
- Whether customer-facing and internal notes should be separated.
- Where exports will be stored.
- Who can access the exported files.
- How long they should be retained.
Meeting exports can become durable records. Treat them like work documents, not disposable downloads.
If an API Key Is Exposed
If a Fathom API key appears in a screenshot, ticket, shared doc, or support bundle:
- Revoke or rotate the key in Fathom.
- Remove the exposed copy where possible.
- Check what tool or person received it.
- Review whether meeting data may have been accessed.
- Update the process that exposed it.
The best fix is prevention, but rotation should be fast and boring when needed.
FAQ
Should I paste my Fathom API key into any exporter?
Only use tools you trust and understand. Review the tool's privacy policy and data path before pasting a key.
Does Koda Sidecar store my Fathom API key on its servers?
The Fathom app is designed to store settings locally in Chrome and send API requests directly to Fathom, not through Koda Sidecar servers.
Are Fathom exports sensitive?
Often yes. Meeting exports can include customer names, transcripts, action items, decisions, and internal context.
Should every meeting transcript be exported?
No. Export transcripts when the detail is needed. For many workflows, a reviewed summary and action item list are enough.
CTA
Koda Sidecar's Fathom Action Items & Exporter helps users review action items and export meeting records from Chrome using their own Fathom API key.