PedibeeDocs

Authentication

API keys, what each one may do, and keeping them safe.

Every request carries an API key in the Authorization header:

Authorization: Bearer kps_9Xb2…

A key looks like kps_ followed by 40 letters and digits. Session cookies from the dashboard never work on the API, and a key never works in the dashboard.

Creating a key

Managers and the owner of a workspace create keys in Settings → API keys:

Name it

Something that says where it's used, e.g. CRM sync or Website sign-ups.

Choose its access

For companies, contacts and lists, pick No access, Read or Read and write. Turn on Emails: Send only if it should send email, and pick which connected Gmail it sends from.

Choose when it expires

Never, or after 30, 90 or 365 days.

Confirm and copy

Enter your password (accounts that sign in only with Google skip this). The key is shown once — copy it into your server's secrets. Pedibee stores only a fingerprint of it, so it can't be shown again; if you lose it, create a new one.

A workspace can have up to 25 keys.

Scopes

Each call needs one scope. Write includes read: a key with contacts:write can also read contacts.

ScopeShown asAllows
leads:readCompanies: ReadListing and reading companies
leads:writeCompanies: Read and writeCreating, updating and deleting companies
contacts:readContacts: ReadListing and reading contacts and custom fields
contacts:writeContacts: Read and writeCreating, updating and deleting contacts and custom fields
lists:readLists: ReadListing and reading lists
lists:writeLists: Read and writeCreating, updating and deleting lists and their members
email:writeEmails: SendSending email from the key's Gmail

Scopes also guard people's details elsewhere: getting a company includes its people in full only for a key that can read contacts, and adding people to a list by email also needs contacts:write, because it can create contacts.

Who a key acts as

A key acts as the person who created it, with their current role:

  • If they're demoted to member or removed from the workspace, their keys are revoked.
  • If they leave, their keys stop working.
  • What a key may change is never more than its creator may change in the dashboard.

Changing and revoking keys

In Settings → API keys you can rename a key or change its access without changing the key itself. Taking access away works at once; adding access asks for your password again. Revoke stops a key immediately and for good.

Keys are for servers

Requests with an Origin header — sent from a web page — are refused with 403. Call the API from your backend, a serverless function or a script, never from code that runs in someone's browser or app.

On this page