This guide covers API keys for REST API access. AI agents (Claude, Cursor,
Windsurf, etc.) connect through the MCP server,
which uses its own authentication flow rather than API keys.
Prerequisites
- You must be an Owner to manage API keys
- Admins and Users cannot create, view, or revoke API keys
Creating an API Key
To create a new API key:- Navigate to Settings > Security > API Keys
- Click Create API Key
- Enter a descriptive name (e.g., “Production CRM Integration”)
- Configure permissions (see below)
- Optionally set an expiration date
- Click Create
The full API key is displayed only once after creation. Copy it immediately
and store it securely. You cannot retrieve the full key later.
API Key Format
Bizzy API keys are prefixed withsk_ followed by a long random secret:
sk_- Indicates a secret key- Followed by a unique random string
sk_ prefix plus the last four characters, e.g. sk_a1b…c3d4) so
you can identify a key without exposing it.
Setting Permissions
API keys support fine-grained permissions that control which resources the key can access and what actions it can perform.Permission Structure
Each permission pairs a resource with an access level:
For each resource, leave it at None or enable Read, Write, or both.
businesses, contacts, customers, emailTemplates, invoices,
invoices.payments, and properties also offer Delete.
Available Resources
Read on Email Templates includes reading Marketing Opt-ins, but Write
doesn’t include writing them. For a key that records or withdraws opt-ins,
enable Read on Email Templates or Marketing Opt-ins, and Write on
Marketing Opt-ins.
To delete records, enable Read, Write, and Delete on the resource — for
example, all three on Contacts to delete contacts and their addresses,
emails, and phone numbers. Deleting customer transactions also takes Read and
Write on Invoice Payments. Domains has no Delete: delete domains and DNS
records in the dashboard.
To delete property definitions, enable Read, Write, and Delete on
Properties.
To read or set property values on contacts, customers, or businesses, also
enable Read on that resource — for example, Read and Write on Properties
plus Read on Contacts to set contact properties.
Common Permission Patterns
Read-only reporting key — enable Read oncontacts and customers.
Full contact management — enable both Read and Write on contacts.
Domain automation — enable Read and Write on domains only.
Grant the narrowest set that the integration needs; anything you do not
explicitly enable is denied.
Key Expiration
Set an expiration date to automatically disable API keys after a certain period:Expired keys return a
401 Unauthorized error. Create a new key before the
old one expires to avoid service interruption.Monitoring Key Usage
Track API key activity from the API Keys dashboard:
Use the “Last Used” timestamp to identify unused keys that should be revoked.
Revoking Keys
To revoke an API key:- Navigate to Settings > Security > API Keys
- Find the key to revoke
- Click Delete
- Confirm the action
Deleted keys cannot be restored. Any application using the key loses access
immediately.
When to Revoke
Revoke API keys immediately when:- A key may have been compromised
- An employee with key access leaves the business
- An integration is decommissioned
- A key hasn’t been used in 90+ days
Security Best Practices
Key Storage
- Never commit API keys to version control
- Use environment variables or secret management services
- Restrict file permissions on configuration files containing keys
Key Rotation
Regularly rotate API keys to limit exposure from potential leaks:- Create a new key with the same permissions
- Update your application to use the new key
- Verify the new key works in production
- Revoke the old key
Principle of Least Privilege
Grant only the permissions each integration needs:- Read-only keys for reporting and analytics
- Resource-specific keys for focused integrations
- Separate keys for separate applications
Audit Regularly
Review your API keys monthly:- Remove unused keys (no activity in 90+ days)
- Verify permissions match current requirements
- Check expiration dates and rotate as needed
Troubleshooting
Common Errors
Debugging Permission Issues
If your API key returns403 Forbidden:
- Check the error response for the required permission
- Compare against your key’s configured permissions
- Update the key or create a new one with correct permissions
Next Steps
API Introduction
Learn how to use the Bizzy API
Authentication
Understand API authentication methods