Authentication & scopes
Every request carries an API Key as a bearer token:
Authorization: Bearer lr_live_ab12cd34_…
Keys are never accepted in the query string. A request with no key, or with one that is unknown, expired or revoked, gets 401 with WWW-Authenticate: Bearer.
Who owns a key
A key belongs to your agency (the Tenant), not to a person, so an integration keeps working when someone leaves. Only a Tenant Admin can create, rotate or revoke keys, under Integrations → API keys; every one of those actions goes into the audit log. The console also shows when and from which IP address each key was last used.
What a key writes is labelled "via API: key name" in the console. GET /v1/tenant answers which agency a key belongs to (its slug and name), whatever the key's scopes.
Scopes
A key can only do what its scopes allow; anything else is 403.
leads:read— read Leads, Inquiries, Lead Criteria, matches and Lead Property Links; listlead.*andinquiry.*events.leads:write— create, edit and archive Leads, link Properties, set Lead Criteria. Includesleads:ingest.leads:ingest— onlyPOST /v1/leads:ingest. A form or bot can push Leads in without being able to read any.activities:read— read Activities and listactivity.*events.activities:write— create, edit, complete and delete Activities.webhooks:manage— register, change and remove webhook endpoints, read their delivery logs and redeliver.properties:read— read listings.
Give each integration its own key with the fewest scopes it needs. A key can be rotated (a new secret, same name and scopes) or revoked at any time.
Subscription state
API calls follow the same rules as the console: while your subscription is read-only, writes answer 402 and reads keep working. Ingestion is the exception — POST /v1/leads:ingest keeps accepting Leads, so none are lost. A suspended account answers 503.
Demo accounts cannot create API Keys.