ClearTalk
Developers

Authentication & API keys

Create an API key, send it either of two ways, and understand what it can reach.

Every public API request authenticates with an organization-scoped API key.

The full key is shown exactly once, in the dialog where it's created. Copy it into a password manager or your secret store before closing that dialog — a lost key can't be recovered, only revoked and replaced.

Creating a key

In your dashboard: Integrations → API access → Generate key. Name it after the system that will use it (e.g. "GoHighLevel", "Zapier", "Production").

The full key — it starts with ct_ — is shown exactly once, in the dialog where it's created. Copy it into a password manager or your system's secret store before clicking Done; afterwards the dashboard only ever shows a masked prefix. A lost key can't be recovered — revoke it and generate a new one.

Keys belong to the organization, not the person who created them, so they keep working if that person leaves the team.

Sending the key

Either header works — same key, pick whichever fits your caller:

# Standard bearer token:
curl -H "Authorization: Bearer ct_your_key" ...

# Or, if your platform reserves the Authorization header for its own auth:
curl -H "X-API-Key: ct_your_key" ...

Headers only

Never put the key in a URL (?key=...) or a request body. URLs end up in server logs, proxy logs, and browser history; headers don't. If a key has ever traveled in a URL, treat it as exposed — rotate it.

Scope

A key reaches every endpoint in the API reference — not just triggering conversations, but contacts, campaigns, results, scheduling, and configuration too — with full access to its organization. Treat it like an owner's password: keep it server-side, never in a browser or a mobile app.

The boundary is the organization. There is no organization ID in any URL — the key is the tenant context — and a resource ID from another organization returns the same 404 as one that doesn't exist.

Revoking

Integrations → API access → Revoke next to the key. Revocation is immediate: any system using that key loses access on its next request. Rotate keys by generating the replacement first, updating your systems, then revoking the old one.

Errors

StatusMeaning
401Missing, malformed, or revoked key.
404The resource doesn't exist — or belongs to a different organization.

On this page