API keys

An API key lets a program call BunnyCRM without a person signing in. Typical uses are a website form that saves a newsletter subscriber, or a script that reads data on your behalf.

There are two kinds of key:

Kind Belongs to Use it for
User key Your user account Scripts that act as you. It has the same access as you.
Workspace key A workspace Public integrations such as a website "subscribe" form. Data goes into that workspace.

Prefer a workspace key for anything that runs on a website or a server shared by others.

Create a key

  1. Sign in and open User > API Keys (your own keys) or Workspace > API Keys (workspace keys).
  2. Pick a Validity: 1 day, 1 week, 1 month, 3 months, 6 months, 1 year or 2 years (default).
  3. Click Create API key.
  4. Copy the username and the secret. The secret is shown only once. If you lose it, delete the key and create a new one.

Limits: up to 5 user keys per user and 5 workspace keys per workspace.

Choose the shortest validity that works. When a key expires it stops working immediately and is removed automatically. Create a new one before then.

Create a key with the API

bashCopy
curl -u 'YOUR_USERNAME:YOUR_PASSWORD' \
  'https://auth.bunnycrm.com/v1/api_key/create?boType=user&validity=1w'
Parameter Values
boType user (default) or ws for a workspace key. A workspace key needs a workspace selected (X-TenantId header).
validity 1d, 1w, 1m, 3m, 6m, 1y, 2y. Default 2y. Any other value returns 400.

POST /v1/api_key/create accepts the same choice as "validity" in a JSON body.

The response contains username and password. The password is the secret, and it is never returned again.

Use a key

A key is a username and a secret, sent as HTTP Basic credentials.

With curl's -u option:

bashCopy
curl -i -u 'API_KEY_USERNAME:API_KEY_SECRET' 'https://auth.bunnycrm.com/v1/api_key/test'

Or send the header yourself. API_KEY_VALUE is username:secret encoded as Base64:

bashCopy
curl -i -H 'Authorization: Basic API_KEY_VALUE' 'https://auth.bunnycrm.com/v1/api_key/test'

To build the value on a command line:

bashCopy
printf '%s' 'API_KEY_USERNAME:API_KEY_SECRET' | base64

Test a key

GET /v1/api_key/test tells you whether a key works.

A working key returns 200:

jsonCopy
{
  "valid" : true,
  "name" : "8ncT",
  "type" : "workspace",
  "username" : "20260912-104902512-00002",
  "dateExpires" : "2026-09-29T14:03:08.857824"
}

The secret is never included in the response.

Status Meaning
200 The key is valid.
401 Wrong username or secret, or the key has expired.
400 The request was authenticated some other way (for example a signed-in session), not with an API key.

Repeated wrong guesses count as failed logins and can temporarily lock the username.

Example: subscribe an email to a newsletter

A workspace key can add a subscriber to that workspace. This is what the newsletter form on a website does:

bashCopy
curl -i -X POST 'https://crm-api.example.com/v1/newsletter_subscriber/sub' \
  -H 'Authorization: Basic API_KEY_VALUE' \
  -H 'Content-Type: application/json' \
  -d '{"email":"reader@example.com","listName":"my-website"}'

A successful call returns 201 and the subscriber appears in that workspace's subscribers. A user key cannot do this, because it has no workspace.

Replace crm-api.example.com with your CRM API host.

Manage keys

Action How
List keys API Keys page, or GET /v1/api_key?boType=user (boType=ws for workspace keys)
Delete (revoke) a key The trash icon on the page, or DELETE /v1/api_key/{id}
See when a key was last used The Last used column (updated at most once a minute)

You can delete only your own keys, or your workspace's keys. Deleting a key stops it working at once. The list never shows secrets.

Keep keys safe

  • Treat the secret like a password. Do not commit it to source control or share it.
  • A key authenticates as its owner. A user key can do what you can do.
  • A key placed in a public web page can be read by anyone who opens the page. For a public form, use a workspace key, give it a short validity, and rotate it: create a new key, deploy it, then delete the old one.
  • Delete keys you no longer use.