There are two kinds of key:
| Kind | Belongs to | Use it for |
|---|---|---|
| User key | Your user account | Scripts that act as you. It has the same access as you. |
| Workspace key | A workspace | Public integrations such as a website "subscribe" form. Data goes into that workspace. |
Prefer a workspace key for anything that runs on a website or a server shared by others.
Create a key
- Sign in and open User > API Keys (your own keys) or Workspace > API Keys (workspace keys).
- Pick a Validity: 1 day, 1 week, 1 month, 3 months, 6 months, 1 year or 2 years (default).
- Click Create API key.
- Copy the username and the secret. The secret is shown only once. If you lose it, delete the key and create a new one.
Limits: up to 5 user keys per user and 5 workspace keys per workspace.
Choose the shortest validity that works. When a key expires it stops working immediately and is removed automatically. Create a new one before then.
Create a key with the API
curl -u 'YOUR_USERNAME:YOUR_PASSWORD' \
'https://auth.bunnycrm.com/v1/api_key/create?boType=user&validity=1w'
| Parameter | Values |
|---|---|
boType |
user (default) or ws for a workspace key. A workspace key needs a workspace selected (X-TenantId header). |
validity |
1d, 1w, 1m, 3m, 6m, 1y, 2y. Default 2y. Any other value returns 400. |
POST /v1/api_key/create accepts the same choice as "validity" in a JSON body.
The response contains username and password. The password is the secret, and it is never returned again.
Use a key
A key is a username and a secret, sent as HTTP Basic credentials.
With curl's -u option:
curl -i -u 'API_KEY_USERNAME:API_KEY_SECRET' 'https://auth.bunnycrm.com/v1/api_key/test'
Or send the header yourself. API_KEY_VALUE is username:secret encoded as Base64:
curl -i -H 'Authorization: Basic API_KEY_VALUE' 'https://auth.bunnycrm.com/v1/api_key/test'
To build the value on a command line:
printf '%s' 'API_KEY_USERNAME:API_KEY_SECRET' | base64
Test a key
GET /v1/api_key/test tells you whether a key works.
A working key returns 200:
{
"valid" : true,
"name" : "8ncT",
"type" : "workspace",
"username" : "20260912-104902512-00002",
"dateExpires" : "2026-09-29T14:03:08.857824"
}
The secret is never included in the response.
| Status | Meaning |
|---|---|
200 |
The key is valid. |
401 |
Wrong username or secret, or the key has expired. |
400 |
The request was authenticated some other way (for example a signed-in session), not with an API key. |
Repeated wrong guesses count as failed logins and can temporarily lock the username.
Example: subscribe an email to a newsletter
A workspace key can add a subscriber to that workspace. This is what the newsletter form on a website does:
curl -i -X POST 'https://crm-api.example.com/v1/newsletter_subscriber/sub' \
-H 'Authorization: Basic API_KEY_VALUE' \
-H 'Content-Type: application/json' \
-d '{"email":"reader@example.com","listName":"my-website"}'
A successful call returns 201 and the subscriber appears in that workspace's subscribers. A user
key cannot do this, because it has no workspace.
Replace crm-api.example.com with your CRM API host.
Manage keys
| Action | How |
|---|---|
| List keys | API Keys page, or GET /v1/api_key?boType=user (boType=ws for workspace keys) |
| Delete (revoke) a key | The trash icon on the page, or DELETE /v1/api_key/{id} |
| See when a key was last used | The Last used column (updated at most once a minute) |
You can delete only your own keys, or your workspace's keys. Deleting a key stops it working at once. The list never shows secrets.
Keep keys safe
- Treat the secret like a password. Do not commit it to source control or share it.
- A key authenticates as its owner. A user key can do what you can do.
- A key placed in a public web page can be read by anyone who opens the page. For a public form, use a workspace key, give it a short validity, and rotate it: create a new key, deploy it, then delete the old one.
- Delete keys you no longer use.