InboxTender API

Authentication

Workspace API keys, the Bearer header, and rate limits.

API keys

Keys are minted by a workspace owner in the dashboard: Assistant → API access. A key looks like it_live_ followed by 48 hex characters, and it is shown once — we store only a hash, so copy it when you create it.

  • Up to 5 active keys per workspace. Name them after what uses them ("Website form", "Zapier") so revoking is painless.
  • Revoke instantly from the same card; requests with a revoked key start failing with 401 immediately.
  • API access is part of the Responder and Front Desk plans.

Permissions

Choose permissions when creating a key. Existing keys retain contacts-only access. Read, draft, and send permissions are separate; see messaging scopes. Name each agent key so internal operation records identify the operator.

Sending the key

Pass it in the Authorization header on every request:

curl https://api.inboxtender.com/api/v1/contacts \
  -H "Authorization: Bearer it_live_…"

Treat keys like passwords: server-side only, never in a browser bundle or a public repo. If a key leaks, revoke it and mint a new one — the swap takes seconds.

Rate limits

Each key may make 120 requests per minute. Past that, requests answer 429 with a Retry-After header (in seconds) — wait that long and retry.

On this page