The API and API keys
Creating a key, what it can reach, and how requests are limited and logged.
By PrimemgrUpdated How we research and check this
Settings → API keys creates a key for another system to use. You choose exactly what it may do, from the same permissions your team members have; a key can never manage your team, roles or billing. The key is shown once, so copy it then.
What it can reach
Customers and assets can be read, created, changed and deleted. Jobs can be read, created and updated. Quotes, invoices, payments, bookings, items and time entries can be read. The full reference is published as an OpenAPI document at /api/v1/openapi.json, and AI assistants can connect through MCP with the same key and the same limits.
Safe retries, limits and records
Send an Idempotency-Key header when creating something and a retried request will not create it twice. Requests are rate limited. Every request a key makes is recorded for 90 days, and each key shows when it was last used. If a key is ever exposed, revoke it, which stops it at once, and ask support for its request history.
Webhooks
Settings → Webhooks sends signed notifications to your own systems. Each endpoint has a signing secret, shown once, and failed deliveries are retried. Today you can add endpoints and send test deliveries; notifications for everyday activity are being rolled out.