Skip to content
← What’s New

API keys: let the programs you use read and write your records

Give Zapier, your website or a developer's program a key to add clients, create jobs, take leads and book visits, only as far as you allow, with every call logged. On every plan.

Sample business
The API keys panel on the Integrations page: a Zapier key that may read and write clients and leads and manage webhooks, and a Website booking key that may read clients and book appointments, each Active, with who issued it and whether it has been used.
The API keys panel on the Integrations page: a Zapier key that may read and write clients and leads and manage webhooks, and a Website booking key that may read clients and book appointments, each Active, with who issued it and whether it has been used.

Webhooks told other software what happened here. Now other software can do something about it. Under Integrations → API keys, an Owner makes a key for a program they choose — Zapier, the booking on their website, a script a developer writes for them — and ticks what it may do: read or write clients, jobs, leads and appointments, read invoices, and manage its own webhooks.

What a key writes goes through the same rules as your own work and is recorded under its name, so a client Zapier added says Zapier (API key) added it, and a visit your website booked lands on your calendar with your reminders. A key never charges a card, refunds, deletes your records or sends an invoice: invoices can be read, and money still moves only through your console and your customers’ own pages.

The key is shown once. Each one on the list says what it may do, who made it and when it was last used, and Recent calls shows what it asked for and how it was answered over the last thirty days — never what it sent, so no customer’s details are in the log. Revoke stops a key the moment you confirm, and it stays on the list so what it made still says who made it. A Manager sees the keys and their calls; only the Owner changes them.

For whoever builds the program, API for developers documents every address, field and scope, the errors, paging and limits, with an example for each, written from the same contract the API is held to. A program can subscribe itself to your webhooks too, so connecting a tool and disconnecting it no longer needs you to copy an address across.

Keys are on every plan, up to twenty at once. What a key can reach and what’s yours to keep safe is in the Terms of Use, section 8.13, and what we keep about a key is in the Privacy Policy, section 4.18.

Where to find it Start free