The REST API uses API tokens sent as bearer tokens. A token is tied to the organization selected when it was issued; changing your organization in the app does not retarget that token.
Owners and administrators can create and manage API tokens. The organization needs an active trial or subscription to use the REST API.
Create an API token
- Select the organization to connect.
- Open Settings → API.
- Click Create API Token and give it a descriptive name, such as
Reporting automation.
- Copy the token when shown. You cannot view the full token again after closing the dialog.
- Store it in a password manager, secrets manager, or your integration’s protected settings.
Do not share tokens in email, support chat, or public code. If token setup fails, contact support with the error, not the token.
Pass the token in requests
Send Authorization: Bearer YOUR_API_TOKEN and request JSON responses:
Use GET /me to confirm the token’s organization before sending requests or changing group membership.
Access by role
The token follows the team member’s role. Owners and administrators can use the people, groups, documents, and request endpoints. A token tied to a Group Manager can use GET /me, but organization-wide REST endpoints return 403 Forbidden.
Error responses
See API errors for other responses.
Revoke a token
Open Settings → API to see active tokens, who issued them, their expiry, and last use. Click Revoke when a token is no longer needed or may have been exposed.
Update integrations to use a replacement token before revoking one they still need.
Zapier and AI connections
Zapier and ChatGPT or Claude use OAuth sign-in and consent instead of this API-token setup. Last modified on September 26, 2026