Start with the APIAuthentication
Authentication
The same aivk_ credential as the product. REST is a scope group, not a second secret.
Bearer scheme. aivk_ prefix. No query-string keys. No cookies. Revoking the key immediately rejects subsequent public REST calls.
Scopes
| In the product | Scope | Unlocks |
|---|---|---|
| Contacts: Read / Write | rest.crm.contacts.read / .write | GET list/id · POST / PATCH / upsert |
| Companies: Read / Write | rest.crm.companies.read / .write | GET · POST / PATCH / upsert |
| Deals: Read / Write | rest.crm.deals.read / .write | GET · POST / PATCH and GET /stages |
| Notes / Tasks | rest.crm.notes.* · rest.crm.tasks.* | Record notes and tasks |
| Webhooks / Members / Tags | rest.crm.webhooks.* · members.read · tags.* | Subscriptions, owners, CRM catalog |
| Meetings | rest.meetings.read · transcript.read | List/detail · separate transcript |
| Inbox | rest.conversations.read / .messages.read / .write | Threads, messages, reply and ops |
| Sequences | rest.sequences.read / .write | List/get · POST enroll |
Write always stores the matching read. A key with only Contacts scopes 403s on /companies, /deals, /meetings, /conversations and /sequences. Transcript and inbox messages are separate grants.
401 vs 403
401: the host does not accept this credential (missing, garbage or revoked). 403: the credential is valid and the key is missing a REST scope. An id from another organization is 404, not 403.