DOCUMENTATION

Keep your key on the server.

Keys are credentials. Treat them like passwords.

Full API reference and interactive request explorer →

Use least privilege

Scopes are messages:read, messages:write, calls:read, calls:write, and resources:read. Keys may additionally restrict numbers and bots.

Rotate and revoke

Secrets are shown once. Use separate keys for integrations and revoke keys you no longer need. Live keys must never appear in frontend code.

Organisation boundaries

Each key is bound to its organisation and environment. Requests use the organisation OAuth account configured in CRM OAuth Setup; scopes and resource restrictions narrow its CRM permissions.

Pilot access requires verified organisation configuration. Never expose a live API key in frontend code.

View the versioned OpenAPI contract