Connect your systems. Control their access.

Connect CRM integrations with workspace service accounts and scoped, expiring API keys. Use versioned REST endpoints, retry-safe writes and request history.

Give each integration its own identity

Owners and administrators create named service accounts in Settings - Developer access. Choose the current workspace objects and actions that the integration needs, then approve with your current password. Read includes every field and owner in an approved object. Newly created objects are not granted automatically.

Each key has its own name, narrower permissions and expiry. Its secret appears once, hidden until you choose to show or copy it. Store it privately on the server that runs the integration. It cannot sign in to the application, manage billing or configure outreach providers.

Keep CRM changes consistent

Use the versioned REST API for people, companies, leads, opportunities, tasks and approved custom objects. Read schemas and records, create or update permitted records, or add an internal note. Mutations require an idempotency reference so an identical retry returns the original result without duplicating work. Record changes and notes use the shared audit and event runtime.

Financial objects allow reading and internal notes through this API. Invoice issuing, expense approval and payment recording remain in their dedicated workflows. The API supports up to 120 requests per minute per key alongside the application’s general limit.

Reduce or end access deliberately

Rotate a key to issue a replacement and revoke the old credential together. Revoke a key, or disable its service account, to block future requests after in-flight work completes. Reducing an account’s permissions also narrows its existing keys; expanding the account later does not silently restore those grants.

Request history shows normalized operations and status codes without credentials or customer payloads. History is written after a response, so a process interruption can omit a terminal row; authenticated usage is metered before dispatch. Signed outbound customer webhooks, SDKs and fine field or team permission policies are not included in this release.

Start with your workspace.

Read the setup guide

Give your team
one place to work.

Start your 15-day free trial. Set up the workspace around your business.

Start your free trial