Skip to content
Pitch2SaleDevelopers
Open the app
Early access: these pages are being written and reviewed. Facts in the header boxes come straight from the product.

API keys

A personal access token (PAT) is the recommended credential for integrations. It looks like pat_ followed by 64 hex characters and acts as the user who created it (see Authentication).

In the app: Settings → API keys → create. Your role needs the settings.api_keys.create permission.

With the API (authenticated as the user who will own the key):

Terminal window
curl -X POST "https://api.pitch2sale.com/api/v1/settings/api-keys" \
-H "Authorization: Bearer <token>" \
-H "Content-Type: application/json" \
-d '{ "label": "Warehouse sync", "scopes": ["read:leads", "read:opportunities"] }'

label is required (1–100 characters). The label must be unique among your keys, revoked ones included; a duplicate returns 409. scopes is optional; see Scopes. The response is 201:

{
"key": {
"id": "…",
"label": "Warehouse sync",
"token_prefix": "pat_…",
"scopes": ["read:leads", "read:opportunities"],
"last_used_at": null,
"revoked_at": null,
"created_at": "…",
"updated_at": "…"
},
"plain_token": "pat_…"
}

plain_token appears in this response only. Pitch2Sale stores a SHA-256 hash of it, so it cannot be shown again. Store it in your secret manager straight away; if you lose it, create a new key.

Terminal window
curl -H "Authorization: Bearer <token>" "https://api.pitch2sale.com/api/v1/settings/api-keys"

Returns { "keys": [ ... ] } with the same fields as key above — never the token itself. token_prefix (the first 8 characters) and last_used_at help you tell keys apart. The list contains the calling user’s own keys, including revoked ones (their revoked_at is set). Requires settings.api_keys.view_own.

Terminal window
curl -X DELETE -H "Authorization: Bearer <token>" \
"https://api.pitch2sale.com/api/v1/settings/api-keys/{id}"

Returns { "message": "API key revoked" }. Requests with that key fail with 401 from then on. Requires settings.api_keys.delete.

A key carries a list of scopes. If you omit scopes or pass an empty array when creating it, the key gets the defaults:

Resource Scopes
Leads read:leads, write:leads
Contacts read:contacts, write:contacts
Opportunities read:opportunities, write:opportunities
Invoices read:invoices, write:invoices
Proposals read:proposals, write:proposals
Projects read:projects, write:projects

Two scopes are opt-in and never granted by default:

  • mcp:read — connect an MCP client and use the read-only tools (MCP server).
  • mcp:write — also use the MCP write tools. A key with mcp:write can use the read tools too.

A key with a non-default scope list holds only the scopes you pass, so a key for MCP that should also call the REST API needs both, for example ["mcp:read", "read:leads"]. Scope strings are not checked against a list: a misspelt scope is stored as-is and grants nothing.