Skip to main content

Start with the APIAuthentication

Authentication

The same aivk_ credential as the product. REST is a scope group, not a second secret.

Bearer scheme. aivk_ prefix. No query-string keys. No cookies. Revoking the key immediately rejects subsequent public REST calls.

Scopes

In the productScopeUnlocks
Contacts: Read / Writerest.crm.contacts.read / .writeGET list/id · POST / PATCH / upsert
Companies: Read / Writerest.crm.companies.read / .writeGET · POST / PATCH / upsert
Deals: Read / Writerest.crm.deals.read / .writeGET · POST / PATCH and GET /stages
Notes / Tasksrest.crm.notes.* · rest.crm.tasks.*Record notes and tasks
Webhooks / Members / Tagsrest.crm.webhooks.* · members.read · tags.*Subscriptions, owners, CRM catalog
Meetingsrest.meetings.read · transcript.readList/detail · separate transcript
Inboxrest.conversations.read / .messages.read / .writeThreads, messages, reply and ops
Sequencesrest.sequences.read / .writeList/get · POST enroll

Write always stores the matching read. A key with only Contacts scopes 403s on /companies, /deals, /meetings, /conversations and /sequences. Transcript and inbox messages are separate grants.

401 vs 403

401: the host does not accept this credential (missing, garbage or revoked). 403: the credential is valid and the key is missing a REST scope. An id from another organization is 404, not 403.