Skip to content
OmniLeadDocs
Sign in

Authenticate with API keys

Create live and test API keys, send them as bearer tokens, and keep them safe.

Available on Agency3 min readLast updated

Every API request is authenticated with an API key sent as a bearer token. Keys belong to a workspace, not to a person, so an integration keeps working when a teammate leaves. The API is available on the Agency plan.

Create a key

Owners and admins can create keys.

  1. Open API settings

    Go to Settings → API.

  2. Start a new key

    Click Create API key.

  3. Name it and choose the mode

    Give the key a name that says where it's used, such as "HubSpot sync" or "Staging", and choose Live or Test.

  4. Create and copy

    Click Create key. Copy the key and store it in your secrets manager or environment variables.

API settings listing keys with their name, prefix, mode and last use

The list in Settings → API shows each key's name, its first characters (for example ol_live_4f9a…), its mode, who created it and when it was last used.

Live and test keys

Live keyTest key
Prefixol_live_ol_test_
Reads your CRMYesYes
Creates, updates and deletes CRM recordsYesYes
Spends credits on search and revealYesNo: search returns page 1 free, reveals are dry runs
Enrolls leads and sends emailYesNo: enrollments are dry runs
livemode in responsestruefalse

Test keys work against your real workspace data, so writes and deletes are real. They're designed to let you build and test an integration without spending credits or emailing anyone.

Send the key

Put the key in the Authorization header with the Bearer scheme, on every request:

curl https://omni.cloudgens.net/api/v1/credits \
  -H "Authorization: Bearer $OMNILEAD_API_KEY" \
  -H "OmniLead-Version: 2026-09-28"

Keys in query strings or request bodies aren't accepted. Requests must use HTTPS; plain HTTP is refused.

When authentication fails

A missing, malformed or revoked key returns 401:

401 Unauthorized
{
  "error": {
    "type": "authentication_error",
    "code": "authentication_failed",
    "message": "No valid API key provided. Send it as `Authorization: Bearer ol_live_…`.",
    "doc_url": "https://omni.cloudgens.net/docs/api/errors#authentication_failed"
  }
}

A valid key on a workspace that isn't on Agency returns 403 with the code permission_denied. If a workspace moves off Agency, its keys stop working until it upgrades again; they aren't deleted.

Revoke a key

  1. Find the key

    In Settings → API, find the key by its name or prefix.

  2. Revoke it

    Click Revoke, then Revoke key to confirm.

Revocation is immediate: the next request with that key gets a 401. Creating and revoking keys is recorded in the audit log.

Keep keys safe

  • One key per integration. If one leaks, you revoke it without breaking the others, and the audit log shows which integration did what.
  • Keep keys on servers. Never put a live key in browser code, a mobile app or a public repository.
  • Rotate regularly. Create the new key, deploy it, then revoke the old one. There's no downtime because both keys work until you revoke.
  • Use test keys in development and CI.

If a key is exposed, revoke it straight away, then check the audit log and the credit history for activity you don't recognise.

Can I limit a key to read-only?

Not yet. Every key can read and write. Use test keys where you don't need to spend credits or send email.

Do API calls count against my seats?

No. Keys aren't seats. Credits spent through the API come from the workspace balance.

How many keys can I create?

There's no fixed limit. Each key has its own rate limit of 120 requests a minute.

What's next