Generate a dedicated workspace API key and secret in the Frontegg admin portal for Terraform, and do not paste the Workspace Settings client ID and secret. Configure one provider block per workspace and per environment ID, and per application ID too if MFA is configured per application, since the provider sends frontegg-application-id on every request.

Context: Official docs (Frontegg Terraform provider): documents a gotcha that trips agents automating Frontegg. The client ID and secret key the provider needs are not the client ID and secret shown in Workspace Settings; you must generate a workspace API key and secret specifically for the provider in the administration portal. The provider also works with only one workspace at a time, so multiple workspaces or environments need multiple provider copies, one environment ID each.