REST API access is available by request on Business. It is enabled per workspace after review rather than switched on automatically with purchase.
HummingDeck API
Create separate API keys for each integration and grant only the access it needs.
CRM reporting
Activeanalytics:readcrm:read- Created
- September 2, 2026
- Expires
- September 2, 2027
- Last used
- Today
Room publishing
Activerooms:readrooms:writedocuments:readdocuments:write- Created
- August 18, 2026
- Expires
- August 18, 2027
- Last used
- Yesterday
API access is switched on per workspace. Owners and admins on Business request it from this section, and the panel above appears once access is granted.
Good API use cases
Request access when a real workflow needs to:
- upload generated documents automatically;
- publish HTML output from an internal system;
- create personalized Share Links from a CRM or sales workflow;
- create a Room with its documents and link, then arrange its tabs and sections;
- find or create companies and contacts;
- retrieve engagement events for an automation or integration.
For a small number of manual uploads, the Document Library is simpler and safer than maintaining an API integration.
For occasional batches, Bulk-generate personalized document links from a CSV or connected Close Smart View. Use the API when link creation needs to run repeatedly inside another system.
Request access
Open Workspace, choose Integrations, and find HummingDeck API. Select Request API access.
The request takes one click. Describing the workflow is optional, and it usually saves a round of email. Useful details:
- the workflow you want to automate;
- expected upload or request volume;
- the file types involved;
- whether you need companies, contacts, shares, Rooms, views, or events.
Workspace owners and admins can send the request. We reply by email when access is switched on.
On plans below Business the section stays visible and locked, and opens your plan options instead.
Create workspace API keys
After access is switched on, a workspace owner or admin returns to Workspace, Integrations, HummingDeck API. Create a separate, clearly named key for each integration or workflow. A workspace can have up to 20 active API keys. A key name can contain 1 to 64 characters and must be unique among active keys, ignoring capitalization and surrounding spaces.
When you create or replace a key, grant only the permissions that integration needs. A write permission includes the matching read permission. The raw key is shown once, so store it in a secret manager. Do not paste it into browser code, an HTML upload, a public repository, a shared document, or a support ticket.
| Permission | What it allows |
|---|---|
rooms:read | View Rooms, tabs, items, links, and labels. |
rooms:write | Create and manage Rooms, tabs, items, links, and labels. |
plan:read | View Mutual Action Plan phases and tasks. |
plan:write | Create and manage Mutual Action Plan phases and tasks. |
analytics:read | View engagement analytics, activity, and captured emails. |
crm:read | Find workspace companies and contacts. |
crm:write | Create or update companies, contacts, and link audiences. |
documents:read | Find documents and read their metadata. |
documents:write | Upload documents and attach documents or URLs to Rooms. |
A key created before named permissions were introduced appears as Legacy API key and keeps all API permissions until you replace it or switch it off.
Every key is permanently bound to the workspace that created it. An API request cannot select another workspace or override this boundary.
Each key expires one year after it is created. Replacing a key switches off that key immediately and shows a new raw key without affecting the workspace's other keys. You can also switch off any key independently; a switched-off key cannot be restored.
The key list shows each key's status, permissions, creation and expiry dates, and most recent use. An expired or switched-off entry can prefill the name and permissions for a new key. Switch off all permanently disables every active key in the workspace at once.
A key also stops authenticating if the person who created it is no longer a workspace owner or admin. Create production keys from a stable owner or admin account, and replace them when responsibility for an integration changes.
Open the technical API reference
Use this Support article for access, credential, and workflow guidance. Use the canonical HummingDeck API reference for current endpoints, authentication, request and response schemas, errors, document uploads, Share Links, companies, contacts, Rooms, views, events, and webhooks.
Browser uploads accept files up to 100 MB. The API document upload endpoint has a 30 MB limit. HTML uploaded through the API must still meet the same static-content and asset requirements as a manual upload.