Authentication
API keys, what each one may do, and keeping them safe.
Every request carries an API key in the Authorization header:
Authorization: Bearer kps_9Xb2…A key looks like kps_ followed by 40 letters and digits. Session cookies from the dashboard never work on the API, and a key never works in the dashboard.
Creating a key
Managers and the owner of a workspace create keys in Settings → API keys:
Name it
Something that says where it's used, e.g. CRM sync or Website sign-ups.
Choose its access
For companies, contacts and lists, pick No access, Read or Read and write. Turn on Emails: Send only if it should send email, and pick which connected Gmail it sends from.
Choose when it expires
Never, or after 30, 90 or 365 days.
Confirm and copy
Enter your password (accounts that sign in only with Google skip this). The key is shown once — copy it into your server's secrets. Pedibee stores only a fingerprint of it, so it can't be shown again; if you lose it, create a new one.
A workspace can have up to 25 keys.
Scopes
Each call needs one scope. Write includes read: a key with contacts:write can also read contacts.
| Scope | Shown as | Allows |
|---|---|---|
leads:read | Companies: Read | Listing and reading companies |
leads:write | Companies: Read and write | Creating, updating and deleting companies |
contacts:read | Contacts: Read | Listing and reading contacts and custom fields |
contacts:write | Contacts: Read and write | Creating, updating and deleting contacts and custom fields |
lists:read | Lists: Read | Listing and reading lists |
lists:write | Lists: Read and write | Creating, updating and deleting lists and their members |
email:write | Emails: Send | Sending email from the key's Gmail |
Scopes also guard people's details elsewhere: getting a company includes its people in full only for a key that can read contacts, and adding people to a list by email also needs contacts:write, because it can create contacts.
Who a key acts as
A key acts as the person who created it, with their current role:
- If they're demoted to member or removed from the workspace, their keys are revoked.
- If they leave, their keys stop working.
- What a key may change is never more than its creator may change in the dashboard.
Changing and revoking keys
In Settings → API keys you can rename a key or change its access without changing the key itself. Taking access away works at once; adding access asks for your password again. Revoke stops a key immediately and for good.
Keys are for servers
Requests with an Origin header — sent from a web page — are refused with 403. Call the API from your backend, a serverless function or a script, never from code that runs in someone's browser or app.