Authentication
Workspace API keys, the Bearer header, and rate limits.
API keys
Keys are minted by a workspace owner in the dashboard: Assistant →
API access. A key looks like it_live_ followed by 48 hex characters,
and it is shown once — we store only a hash, so copy it when you
create it.
- Up to 5 active keys per workspace. Name them after what uses them ("Website form", "Zapier") so revoking is painless.
- Revoke instantly from the same card; requests with a revoked key start
failing with
401immediately. - API access is part of the Responder and Front Desk plans.
Permissions
Choose permissions when creating a key. Existing keys retain contacts-only access. Read, draft, and send permissions are separate; see messaging scopes. Name each agent key so internal operation records identify the operator.
Sending the key
Pass it in the Authorization header on every request:
curl https://api.inboxtender.com/api/v1/contacts \
-H "Authorization: Bearer it_live_…"Treat keys like passwords: server-side only, never in a browser bundle or a public repo. If a key leaks, revoke it and mint a new one — the swap takes seconds.
Rate limits
Each key may make 120 requests per minute. Past that, requests answer
429 with a Retry-After header (in seconds) — wait that long and retry.