Scope note: despite the card's description ("control programmatic access to your organization's data"), this doesn't manage general CRM data API access. It manages keys for exactly five named integrations: Public Chat, Subscription Catalog, Public Webinar, VoIP Recording Uploads, and the E-Signature API. If you're looking for a broader data API, this isn't it — flag that clearly to whoever's reading, don't imply broader scope.
Create and manage API keys that grant one or more of the five specific public-facing integrations access to your organization.
Before you start
Access to Settings → System Security.
Steps
- Go to Settings → System Security → API Access.
- Click Create Key.
- Enter a Label (required, e.g. "Marketing Site") and optionally restrict Allowed Origins (comma-separated; blank allows any origin).
- Check which Scopes this key should have: Public Chat, Subscription Catalog, Public Webinar, VoIP Recording Uploads, E-Signature API (only Public Chat is checked by default).
- Click Create. The full key value is shown exactly once — copy it now, you won't see it again.
To manage an existing key
- Edit Scopes (pencil icon) — change which of the five scopes are granted. Label and Allowed Origins can't be changed after creation.
- Toggle Active/Inactive — pause a key without deleting it.
- Revoke (trash icon) — permanently disables the key; anything using it stops working immediately.
What you'll see
The table shows each key's label, a truncated prefix (the full value is never shown again), scopes, allowed origins, status, and last-used date.
Related articles
Other guides that answer questions close to this one.
The PHI Access Audit
Every read of protected health information anywhere in KamoCRM is recorded as a PHI access record: who (actor), what kind of access (view, list, search, download, export, or disclose), on what record (one of 17 tracked…
Access Blocks Explained
Four related but distinct ways to control who can reach your organization, all on one Settings screen: IP Whitelist — always allowed, and always wins if the same address is also blacklisted. IP Blacklist — permanently…
Detection Rules Explained
A detection rule watches for a pattern of events — a Threshold Count of matching events within a Window of minutes — and automatically fires one or more Response Actions when that pattern is hit: log it only,…