Creating an API Key
- Sign in to the Bizzy Dashboard
- Navigate to Settings > API Keys
- Click Create API Key
- Give your key a descriptive name (e.g., “Production Server” or “Development”)
- Select the permission scopes your key needs
- Click Create and copy your key immediately
Using Your API Key
Include your API key in theAuthorization header of every request using the
Bearer token format:
Permission Scopes
API keys are scoped to specific permissions that control what resources they can access. When creating a key, grant only the permissions your integration needs.Available scopes
No scope grants access to the automations, files, folders, messages, or tasks
endpoints; API keys get
403 Forbidden there.
Permission inheritance
A scope on a resource also covers its child resources, which a403 response
can name in details.required.resource:
contactscoverscontacts.addresses,contacts.emails, andcontacts.phonescustomerscoverscustomers.transactionsbusinessescoversbusinesses.offerings,businesses.online_presences,businesses.physical_presences, andbusinesses.profileemailTemplatescovers readingemailTemplates.optIns, but not recording or withdrawing opt-ins — grantemailTemplates.optIns:writefor thatinvoicescoversinvoices.payments
HTTP methods and permissions
Reading an invoice returns its line items with
invoices:read. Adding,
changing, or removing a line item on a draft invoice requires invoices:read
and invoices:write, not invoices:delete. Creating an invoice requires
businesses:read, customers:read, invoices:read, and invoices:write.
Deleting an invoice requires invoices:read, invoices:write,
invoices:delete, invoices.payments:read, invoices.payments:write, and
invoices.payments:delete.
Deleting a contact, customer, or a record that belongs to a contact, customer,
or business requires read, write, and delete on that resource. For
example, deleting a contact’s phone number requires contacts:read,
contacts:write, and contacts:delete, and deleting a business offering
requires businesses:read, businesses:write, and businesses:delete.
Deleting a customer transaction also requires invoices.payments:read and
invoices.payments:write, because any invoice payment recorded against it is
unlinked from it.
API keys can’t delete domains, subdomains, or DNS records: there is no
domains:delete scope. Delete them in the dashboard instead — see
Delete or transfer a domain.
Creating or updating an email template requires emailTemplates:read and
emailTemplates:write. Deleting one requires emailTemplates:read,
emailTemplates:write, and emailTemplates:delete.
Listing and getting opt-ins requires emailTemplates.optIns:read. Recording or
withdrawing an opt-in requires emailTemplates.optIns:read and
emailTemplates.optIns:write. Opt-ins can’t be deleted, so there is no
emailTemplates.optIns:delete scope.
Listing and getting property definitions requires properties:read. Creating
or updating one requires properties:read and properties:write. Retiring one
with DELETE requires properties:read, properties:write, and
properties:delete.
Property values on a contact, customer, or business also require read on that
resource. For example, listing a contact’s properties requires
properties:read and contacts:read; setting or updating a value adds
properties:write; deleting one adds properties:write and
properties:delete. Writing a value doesn’t require write on the contact,
customer, or business.
Authentication Errors
If authentication fails, you’ll receive a401 Unauthorized response:
- Missing
Authorizationheader - Invalid or revoked API key
- Malformed Bearer token (missing “Bearer ” prefix)
403 Forbidden response:
Security Best Practices
Never commit API keys to version control
Never commit API keys to version control
Use environment variables or a secrets manager to store your API keys. Add
.env files to your .gitignore.Use separate keys for each environment
Use separate keys for each environment
Create different API keys for development, staging, and production. This
limits the blast radius if a key is compromised.
Grant minimum required permissions
Grant minimum required permissions
Follow the principle of least privilege. Only grant the specific permissions
your integration needs. A read-only dashboard doesn’t need write access.
Rotate keys regularly
Rotate keys regularly
Periodically create new API keys and deprecate old ones. This limits the
window of exposure if a key is leaked.
Monitor API key usage
Monitor API key usage
Review your API key activity in the dashboard regularly. Revoke any keys showing suspicious activity immediately.