Authentication & API keys
Create an API key, send it either of two ways, and understand what it can reach.
Every public API request authenticates with an organization-scoped API key.
The full key is shown exactly once, in the dialog where it's created. Copy it into a password manager or your secret store before closing that dialog — a lost key can't be recovered, only revoked and replaced.
Creating a key
In your dashboard: Integrations → API access → Generate key. Name it after the system that will use it (e.g. "GoHighLevel", "Zapier", "Production").
The full key — it starts with ct_ — is shown exactly once, in the dialog where it's created. Copy it into a password manager or your system's secret store before clicking Done; afterwards the dashboard only ever shows a masked prefix. A lost key can't be recovered — revoke it and generate a new one.
Keys belong to the organization, not the person who created them, so they keep working if that person leaves the team.
Sending the key
Either header works — same key, pick whichever fits your caller:
# Standard bearer token:
curl -H "Authorization: Bearer ct_your_key" ...
# Or, if your platform reserves the Authorization header for its own auth:
curl -H "X-API-Key: ct_your_key" ...Headers only
Never put the key in a URL (?key=...) or a request body. URLs end up in server logs, proxy logs, and browser history; headers don't. If a key has ever traveled in a URL, treat it as exposed — rotate it.
Scope
A key reaches every endpoint in the API reference — not just triggering conversations, but contacts, campaigns, results, scheduling, and configuration too — with full access to its organization. Treat it like an owner's password: keep it server-side, never in a browser or a mobile app.
The boundary is the organization. There is no organization ID in any URL — the key is the tenant context — and a resource ID from another organization returns the same 404 as one that doesn't exist.
Revoking
Integrations → API access → Revoke next to the key. Revocation is immediate: any system using that key loses access on its next request. Rotate keys by generating the replacement first, updating your systems, then revoking the old one.
Errors
| Status | Meaning |
|---|---|
401 | Missing, malformed, or revoked key. |
404 | The resource doesn't exist — or belongs to a different organization. |