Customisation and integrations

API tokens and webhooks

Connect external systems through scoped API tokens and signed outbound webhooks.

How it works

Connect systems with explicit access and delivery history

Create scoped API tokens and signed outbound webhooks for supported integrations. Separate read and write scopes, then inspect delivery attempts and retries when an endpoint is unavailable.

01

What it covers

Separate read and write scopes, inspect delivery history and let failed deliveries retry.

02

In practice

Tokens do not grant billing, account-authentication or integration-secret administration.

When to use it

Useful situations

  • Give an external reporting tool read-only API access.
  • Send signed events to an approved integration endpoint.
  • Review a failed delivery and its retry history.

A working path

How the work moves

  1. Create

    Issue a scoped API token or configure the supported webhook destination.

  2. Connect

    Use the documented scope or signature contract in the external system.

  3. Monitor

    Inspect delivery history and address endpoint failures before relying on retries.

Illustrative scenario

warehouse sync

An administrator creates a narrowly scoped token for a reporting sync and reviews outbound webhook delivery after the endpoint is changed. The integration owner can give one external service only the access it needs, then use delivery history to diagnose an endpoint problem without sharing a staff sign-in.

Before you start

What to check

  • Tokens have explicit read or write scopes and should be stored securely.
  • Tokens do not grant billing, account-authentication or integration-secret administration.

Questions about API tokens and webhooks

Useful details before you start.

All questions
Are webhooks signed?

Supported outbound webhooks use a signed delivery contract.

Can a token act as an owner?

No. It has only its granted scopes.

Get started

See your customer work in one place.

Start with the core CRM for free, then add the tools your team needs.