Browse help topics
API

API access and reference

Request API access, create named and scoped workspace API keys, review common automation use cases, and open the technical REST API reference.

Updated September 23, 2026

Examples use sample data. Available controls may vary by plan, role, and product version.

REST API access is available by request on Business. It is enabled per workspace after review rather than switched on automatically with purchase.

Product exampleBased on the live API key panel

HummingDeck API

Create separate API keys for each integration and grant only the access it needs.

CRM reporting

Active
analytics:readcrm:read
Created
September 2, 2026
Expires
September 2, 2027
Last used
Today

Room publishing

Active
rooms:readrooms:writedocuments:readdocuments:write
Created
August 18, 2026
Expires
August 18, 2027
Last used
Yesterday

API access is switched on per workspace. Owners and admins on Business request it from this section, and the panel above appears once access is granted.

Good API use cases

Request access when a real workflow needs to:

  • upload generated documents automatically;
  • publish HTML output from an internal system;
  • create personalized Share Links from a CRM or sales workflow;
  • create a Room with its documents and link, then arrange its tabs and sections;
  • find or create companies and contacts;
  • retrieve engagement events for an automation or integration.

For a small number of manual uploads, the Document Library is simpler and safer than maintaining an API integration.

For occasional batches, Bulk-generate personalized document links from a CSV or connected Close Smart View. Use the API when link creation needs to run repeatedly inside another system.

Request access

Open Workspace, choose Integrations, and find HummingDeck API. Select Request API access.

The request takes one click. Describing the workflow is optional, and it usually saves a round of email. Useful details:

  • the workflow you want to automate;
  • expected upload or request volume;
  • the file types involved;
  • whether you need companies, contacts, shares, Rooms, views, or events.

Workspace owners and admins can send the request. We reply by email when access is switched on.

On plans below Business the section stays visible and locked, and opens your plan options instead.

Create workspace API keys

After access is switched on, a workspace owner or admin returns to Workspace, Integrations, HummingDeck API. Create a separate, clearly named key for each integration or workflow. A workspace can have up to 20 active API keys. A key name can contain 1 to 64 characters and must be unique among active keys, ignoring capitalization and surrounding spaces.

When you create or replace a key, grant only the permissions that integration needs. A write permission includes the matching read permission. The raw key is shown once, so store it in a secret manager. Do not paste it into browser code, an HTML upload, a public repository, a shared document, or a support ticket.

PermissionWhat it allows
rooms:readView Rooms, tabs, items, links, and labels.
rooms:writeCreate and manage Rooms, tabs, items, links, and labels.
plan:readView Mutual Action Plan phases and tasks.
plan:writeCreate and manage Mutual Action Plan phases and tasks.
analytics:readView engagement analytics, activity, and captured emails.
crm:readFind workspace companies and contacts.
crm:writeCreate or update companies, contacts, and link audiences.
documents:readFind documents and read their metadata.
documents:writeUpload documents and attach documents or URLs to Rooms.

A key created before named permissions were introduced appears as Legacy API key and keeps all API permissions until you replace it or switch it off.

Every key is permanently bound to the workspace that created it. An API request cannot select another workspace or override this boundary.

Each key expires one year after it is created. Replacing a key switches off that key immediately and shows a new raw key without affecting the workspace's other keys. You can also switch off any key independently; a switched-off key cannot be restored.

The key list shows each key's status, permissions, creation and expiry dates, and most recent use. An expired or switched-off entry can prefill the name and permissions for a new key. Switch off all permanently disables every active key in the workspace at once.

A key also stops authenticating if the person who created it is no longer a workspace owner or admin. Create production keys from a stable owner or admin account, and replace them when responsibility for an integration changes.

Open the technical API reference

Use this Support article for access, credential, and workflow guidance. Use the canonical HummingDeck API reference for current endpoints, authentication, request and response schemas, errors, document uploads, Share Links, companies, contacts, Rooms, views, events, and webhooks.

Browser uploads accept files up to 100 MB. The API document upload endpoint has a 30 MB limit. HTML uploaded through the API must still meet the same static-content and asset requirements as a manual upload.