Create an API key
An API key lets another app work with your business: add leads, read conversations, send replies. Only admins can create keys.
Updated
Create a key
Open API & Webhooks
In the sidebar, under Connections, click API & Webhooks, then the API keys tab.
Name it and pick permissions
Give it a name you’ll recognize, like “Zapier” or “Website”. Under Permissions, choose the smallest option that works: Read only if the app only needs to look, Zapier / Make / n8n for automations, Full access only for your own developer.
Click Create key and copy it
The key is shown once. Copy it straight into the app that needs it. If you lose it, revoke it and create a new one.
Keep it safe
Treat it like a password
Anyone with the key can act on your business within its permissions. Never post it in a chat, email or website.
Revoke when in doubt
Click Revoke next to a key and anything using it stops working immediately. Webhooks that the key created stop too.
See where it’s used
Each key shows when it was last used, so you can spot keys nobody needs anymore.
Questions
Admins of the business. Managers, agents and doctors can’t see the API & Webhooks page.
No. To protect your number, it can only reply in conversations the customer started. New leads get a first message from OrcaFlo, sent at a safe pace during business hours.
No, it’s only shown once. Revoke it and create a new one.
orca.flo