API Keys
Create and manage API keys for programmatic access to CalyxCRM
Overview
API keys allow you to access CalyxCRM programmatically through the REST API. Each API key is scoped to a single organization and can be used to automate tasks, integrate with external systems, or build custom applications.
Managing API Keys
Accessing the Developers Tab
- Click on your organization name in the sidebar
- Select Settings
- Navigate to the Developers tab
Creating an API Key
- In the Developers tab, click Create API Key
- Enter a descriptive name for the key (e.g., "Production Integration", "CI/CD Pipeline")
- Choose access permissions - Full access or select individual scopes
- Optionally set an expiration date
- Click Create
- Important: Copy the API key immediately. For security reasons, the full key is only shown once and cannot be retrieved later.
API Key Format
API keys follow this format:
caly_XXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXX- Prefix:
caly_(identifies CalyxCRM keys) - Key body: 43 characters of random base64url-encoded data
Only the first 9 characters (e.g., caly_XXXX) are stored and displayed in the UI for identification purposes.
Viewing API Keys
The Developers tab shows a table of all API keys with:
| Column | Description |
|---|---|
| Name | The descriptive name you assigned |
| Key | First 9 characters of the key (prefix) |
| Permissions | "Full access" or the number of scopes assigned |
| Expires | Expiration date, if set |
| Last Used | When the key was last used for an API request |
| Created | Creation date and the user who created it |
Deleting an API Key
- Find the key in the API Keys table
- Click the delete icon in the Actions column
- Type the exact name of the API key to confirm deletion
- Click Delete
Deleted keys are immediately invalidated and cannot be recovered.
Security Best Practices
Key Storage
- Never commit API keys to version control
- Use environment variables or secure secret management systems
- Rotate keys periodically, especially for production systems
Key Permissions
- Use scoped keys to grant only the access each integration needs (e.g.,
records:readfor a read-only dashboard) - Create separate keys for different environments (development, staging, production)
- Create separate keys for different integrations
- Delete keys that are no longer needed
See the API Reference for the full list of available scopes.
Expiration
- Set expiration dates for temporary or contractor access
- Review and rotate long-lived keys periodically
- Monitor the "Last Used" column to identify unused keys
If a Key is Compromised
- Immediately delete the compromised key
- Create a new key
- Update all systems using the old key
- Review API logs for unauthorized access
Using API Keys
Authentication Header
Include your API key in the Authorization header of every request:
Authorization: Bearer caly_your_api_key_hereExample Request
curl -X GET "https://your-domain.com/api/v1/objects" \
-H "Authorization: Bearer caly_your_api_key_here"Error Responses
| Status | Error Code | Description |
|---|---|---|
| 401 | unauthorized | Missing or invalid API key |
| 401 | expired | API key has expired |
| 403 | insufficient_scope | Key doesn't have the required scope for this endpoint |
Rate Limits
API keys are subject to rate limiting to ensure fair usage:
- 100 requests per minute per API key
When rate limited, the API returns a 429 Too Many Requests status with headers indicating when you can retry:
X-RateLimit-Limit: 100
X-RateLimit-Remaining: 0
X-RateLimit-Reset: 1704067200
Retry-After: 45Next Steps
Once you have an API key, see the API Reference for the complete list of available endpoints.