Skip to main content
The Bizzy API uses API keys to authenticate requests. You can create and manage API keys from your organization settings in the dashboard.

Creating an API Key

  1. Sign in to the Bizzy Dashboard
  2. Navigate to Settings > API Keys
  3. Click Create API Key
  4. Give your key a descriptive name (e.g., “Production Server” or “Development”)
  5. Select the permission scopes your key needs
  6. Click Create and copy your key immediately
Your API key is only shown once when created. Store it securely - you won’t be able to see it again. If you lose your key, you’ll need to create a new one.

Using Your API Key

Include your API key in the Authorization header of every request using the Bearer token format:

Permission Scopes

API keys are scoped to specific permissions that control what resources they can access. When creating a key, grant only the permissions your integration needs.

Available scopes

No scope grants access to the automations, files, folders, messages, or tasks endpoints; API keys get 403 Forbidden there.

Permission inheritance

A scope on a resource also covers its child resources, which a 403 response can name in details.required.resource:
  • contacts covers contacts.addresses, contacts.emails, and contacts.phones
  • customers covers customers.transactions
  • businesses covers businesses.offerings, businesses.online_presences, businesses.physical_presences, and businesses.profile
  • emailTemplates covers reading emailTemplates.optIns, but not recording or withdrawing opt-ins — grant emailTemplates.optIns:write for that
  • invoices covers invoices.payments

HTTP methods and permissions

Reading an invoice returns its line items with invoices:read. Adding, changing, or removing a line item on a draft invoice requires invoices:read and invoices:write, not invoices:delete. Creating an invoice requires businesses:read, customers:read, invoices:read, and invoices:write. Deleting an invoice requires invoices:read, invoices:write, invoices:delete, invoices.payments:read, invoices.payments:write, and invoices.payments:delete. Deleting a contact, customer, or a record that belongs to a contact, customer, or business requires read, write, and delete on that resource. For example, deleting a contact’s phone number requires contacts:read, contacts:write, and contacts:delete, and deleting a business offering requires businesses:read, businesses:write, and businesses:delete. Deleting a customer transaction also requires invoices.payments:read and invoices.payments:write, because any invoice payment recorded against it is unlinked from it. API keys can’t delete domains, subdomains, or DNS records: there is no domains:delete scope. Delete them in the dashboard instead — see Delete or transfer a domain. Creating or updating an email template requires emailTemplates:read and emailTemplates:write. Deleting one requires emailTemplates:read, emailTemplates:write, and emailTemplates:delete. Listing and getting opt-ins requires emailTemplates.optIns:read. Recording or withdrawing an opt-in requires emailTemplates.optIns:read and emailTemplates.optIns:write. Opt-ins can’t be deleted, so there is no emailTemplates.optIns:delete scope. Listing and getting property definitions requires properties:read. Creating or updating one requires properties:read and properties:write. Retiring one with DELETE requires properties:read, properties:write, and properties:delete. Property values on a contact, customer, or business also require read on that resource. For example, listing a contact’s properties requires properties:read and contacts:read; setting or updating a value adds properties:write; deleting one adds properties:write and properties:delete. Writing a value doesn’t require write on the contact, customer, or business.

Authentication Errors

If authentication fails, you’ll receive a 401 Unauthorized response:
Common causes:
  • Missing Authorization header
  • Invalid or revoked API key
  • Malformed Bearer token (missing “Bearer ” prefix)
If your key lacks permission for a specific action, you’ll receive a 403 Forbidden response:

Security Best Practices

Use environment variables or a secrets manager to store your API keys. Add .env files to your .gitignore.
Create different API keys for development, staging, and production. This limits the blast radius if a key is compromised.
Follow the principle of least privilege. Only grant the specific permissions your integration needs. A read-only dashboard doesn’t need write access.
Periodically create new API keys and deprecate old ones. This limits the window of exposure if a key is leaked.
Review your API key activity in the dashboard regularly. Revoke any keys showing suspicious activity immediately.

Server-Side Only

API keys should only be used in server-side code. Never expose your API key in client-side JavaScript, mobile apps, or any code that runs in the browser.
If you need to access the Bizzy API from a client application, implement a backend proxy that handles authentication on behalf of your users.
Last modified on September 27, 2026