Skip to main content
Every request needs a team API key. Keys look like csk_<prefix>.<secret> and belong to exactly one team. A key can never read or change another facility’s data.

Send your key

Use either header. They are equivalent.
Treat API keys like passwords. Call the API from a server, never from browser JavaScript or a mobile app where users could read the key.

Create, rotate, and revoke keys

Team admins manage keys under Settings → Integrations → API in the dashboard. See Connect the API for the walkthrough.
  • Name keys after their purpose, such as Website inventory feed, so you know what breaks if you revoke one.
  • Set an expiration for keys handed to contractors. Expired keys return 401 API key expired.
  • Revoke a key the moment it might have leaked. Revoked keys return 401 API key revoked immediately.
  • Rotate by creating a new key, updating the integration, then revoking the old key.

Scopes

Each key carries a list of scopes. A request fails with 403 Missing scope: <scope> when the key lacks the scope that endpoint needs. Each endpoint page lists its scope at the top of the description. Write access is never implied by read access. A key that needs to create cars needs both read:cars (to look them up) and write:cars.
Some writes touch more than one resource. For example, logging a drop-off into a parking spot with POST /cars/{id}/events also needs write:parking.

API turned off

If a team admin turns the API integration off, every key on that team returns 403 API is disabled for this team until it is turned back on. The keys themselves are kept.