Authentication & scopes

Every request carries an API Key as a bearer token:

Authorization: Bearer lr_live_ab12cd34_…

Keys are never accepted in the query string. A request with no key, or with one that is unknown, expired or revoked, gets 401 with WWW-Authenticate: Bearer.

Who owns a key

A key belongs to your agency (the Tenant), not to a person, so an integration keeps working when someone leaves. Only a Tenant Admin can create, rotate or revoke keys, under Integrations → API keys; every one of those actions goes into the audit log. The console also shows when and from which IP address each key was last used.

What a key writes is labelled "via API: key name" in the console. GET /v1/tenant answers which agency a key belongs to (its slug and name), whatever the key's scopes.

Scopes

A key can only do what its scopes allow; anything else is 403.

  • leads:read — read Leads, Inquiries, Lead Criteria, matches and Lead Property Links; list lead.* and inquiry.* events.
  • leads:write — create, edit and archive Leads, link Properties, set Lead Criteria. Includes leads:ingest.
  • leads:ingest — only POST /v1/leads:ingest. A form or bot can push Leads in without being able to read any.
  • activities:read — read Activities and list activity.* events.
  • activities:write — create, edit, complete and delete Activities.
  • webhooks:manage — register, change and remove webhook endpoints, read their delivery logs and redeliver.
  • properties:read — read listings.

Give each integration its own key with the fewest scopes it needs. A key can be rotated (a new secret, same name and scopes) or revoked at any time.

Subscription state

API calls follow the same rules as the console: while your subscription is read-only, writes answer 402 and reads keep working. Ingestion is the exception — POST /v1/leads:ingest keeps accepting Leads, so none are lost. A suspended account answers 503.

Demo accounts cannot create API Keys.