Authentication
We do API Key based authentication.
How to get your API key
As of 2025-12-02, our REST API is an invite only and in BETA.
API keys are managed on the Team profile page.
How to use your API key
There are many ways to send us your API Key. We check for them in the following order, and will use the first one we find.
| Priority | Key | Location | Type | Note |
|---|---|---|---|---|
| 1 | 'authorization' | Header | Bearer | Preferred method on all types of requests |
| 2 | 'x-gt-api-key' | Header | - | - |
| 3 | 'api-key' | Header | - | - |
| 4 | 'api-key' | Query | - | If not able to put the API key in the header, you can include the API key in the |
Example usage
// Search Contacts for 'John'
let search_contacts_url = new URL(`https://api.grouptrackcrm.com/v2/rest/contacts`);
search_contacts_url.searchParams.set('api-key', 'apikey_1234');
search_contacts_url.searchParams.set('filter[name]', 'John');
search_contacts_url.searchParams.set('page[size]', 1);
let {data: contacts, error: search_error} = await fetch(
search_contacts_url,
).then(resp => resp.json());
if (search_error){
// Deal with the error
return;
}
for (let contact of contacts){
// Work with each contact
}
// Create A New Contact
let new_contact_data = {
// contact data...
};
let {data: new_contact, error: create_contact_error} = await fetch(
`https://api.grouptrackcrm.com/v2/rest/contacts`,
{
method: "POST",
headers: {
"Content-Type": "application/json",
"Authorization": `Bearer ${API_KEY}`
},
body: JSON.stringify(new_contact_data)
}
).then(resp => resp.json());
if (create_contact_error){
// Deal with the error
return;
}
// Work with the newly created contact