API Keys
Last updated: September 19, 2026
With an API key, your own system – a CRM or a script, for example – accesses the SilentChat API of your workspace without logging in.
Create an API key
Management → API Keys → "Create API Key"
Owners, admins and developers can create keys.
| Field | Meaning |
|---|---|
| Name | Descriptive name, e.g. "CRM integration" |
| Expiry | 30 days, 90 days (default), 1 year or never |
| Access | Read only (default) or Read and write |
Important: The full key is shown only once. Copy it right away and store it securely.
What a key may do
- Read only: fetch data. Any attempt to create, change or delete something is rejected with
403 ERR_API_KEY_READ_ONLY. - Read and write: create and change conversations, contacts, canned responses and the knowledge base. Not possible: deleting, team, roles, billing, settings, webhooks and further API keys.
GET /api/v1/me/permissions returns what a key may do.
Usage
Send the key in the X-API-Key header:
curl https://api.silentchat.de/api/v1/contacts \
-H "X-API-Key: sk_live_YOUR_KEY"
Every call counts against your plan's monthly API quota.
Recommendations
- As little access as needed – "Read only" is enough for reporting
- Set an expiry – renew keys regularly
- Never in the frontend – API keys belong in your backend, never in code that runs in the browser
- Revoke immediately if compromised – via "Revoke" in the list; the key stops working at once