Connections
Create an API key
Create a key so your website or another system can read and write data in CompanyFlowHQ.
Before you start
- Your plan includes the API (Growth, Pro or Social Agency).
The steps at a glance
Step 1 of 5
Tap Settings in the menu, then tap Developers & API in the "Jump to a section" row (or scroll down to the Developers box).
Settings Jump to a section Website ch… Developers &… Client port… Under API keys, fill in Name, tick What can it do? and choose Expires.
companyflowhq.com/settings CompanyFlowHQ Website Automations Email Market… Team & HR Integrations Settings Guides Settings Search ⌘K Name Website enquiry form Add and update leads, add notes Expires In 90 days Settings Name Website enquiry form Add and update leads, ad… Expires In 90 days Tap Create key.
companyflowhq.com/settings CompanyFlowHQ Website Automations Email Market… Team & HR Integrations Settings Guides Settings Search ⌘K Create key Settings Create key Tap Copy key and store it safely. Then tap I've saved it — you won't see it again.
companyflowhq.com/settings CompanyFlowHQ Website Automations Email Market… Team & HR Integrations Settings Guides Settings Search ⌘K Your new key — copy it now. You won't see it agai… Copy key I've saved it Settings Your new key — copy it now.… Copy key I've saved it Send it in the header: Authorization: Bearer cfhq_live_… (see Read the API guide).
companyflowhq.com/settings CompanyFlowHQ Website Automations Email Market… Team & HR Integrations Settings Guides Settings Search ⌘K Authorization: Bearer cfhq_live_Ab3d… Read the API guide Settings Authorization: Bearer cfhq_live… Read the API guide
What the code looks like
Find it: Settings → Developers and API → Create keyPaste it: The other system's settings, as “Authorization: Bearer <key>”
Not this: whsec_… — that's a webhook signing secret — it checks messages we send you.
✅ How do I know it worked?
- The key is listed with its first letters (cfhq_live_ab12…) and Last used updates when it's used.
⚠️ Common mistakes
ProblemYou put the key in website code anyone can see.FixRevoke it now, and only use keys on servers — never in public web pages.
Problem401 “Send your API key as Authorization: Bearer cfhq_live_…”.FixCheck the header spelling and that you copied the whole key.
