Skip to content

Authentication

Create named API keys in Settings > Connections > API keys. Select only the scopes required by the integration. The raw key is displayed once, so store it in a secret manager when it is created.

Use the key as a bearer token:

Terminal window
curl https://portal.heyx.app/public-api/publicapi.v1.Workspace/Me \
-H "Authorization: Bearer <your-workspace-api-key>" \
-H "Content-Type: application/json" \
-d '{}'

You can also send X-API-Key, but Authorization: Bearer is preferred.

Scopes have the same exact meaning for public Connect endpoints and Workspace MCP tools. Operations that list more than one scope require all of them.

ScopeOperations
me:readMe
customer:readGetCustomer, SearchCustomers, LookupCustomersByIdentifier; also required for PrepareWorkOrder
customer:createCreateCustomer
customer:writePatchCustomer
customer_datafield:writePatchCustomerDataFields
customer_file:createCreate and complete document or photo uploads
customer_file:readList and download-link document or photo records; also required when creating a comment with attachments
customer_comment:createCreateCustomerComment
customer_comment:readListCustomerComments, ListCustomerCommentHistory
customer_activity:readListCustomerTimelineEvents
customer_event:createCreateCustomerEvent
datafield:readListDataFields
correspondence:createAddCorrespondenceMessage
advanced_task:readListAdvancedTaskInstances
advanced_task:updateUpdateAdvancedTaskInstance
advanced_task:attachAttachAdvancedTask
problem:readListProblems, GetProblem, SearchProblems
problem:createCreateProblem
problem:updateUpdateProblem, UpdateProblemStatus
problem:commentAddProblemComment
work_order:readListWorkOrders, GetWorkOrder, SearchWorkOrders; PrepareWorkOrder also requires customer:read
work_order:createCreateWorkOrder
work_order:updateUpdateWorkOrder
work_order:completeCompleteWorkOrder
work_order:cancelCancelWorkOrder
catalog:readListProducts, ListDiscounts, SearchProducts, GetProduct
catalog:writeCreateProduct, UpdateProduct
quote:readGetQuote, ListQuotes
quote:createCreateQuote
quote:updateUpdateQuote, DiscardQuote
quote:confirmConfirmQuote
order:readGetOrder, ListOrders, GetOrderCancellationImpact
order:cancelCancelOrder
payment:readGetPayment, ListPayments, ListRefunds
payment:createCreatePayment
payment:updateRecordManualPayment
payment:refundCreateRefund
invoice:createCreateInvoice
invoice:readGetInvoice, ListInvoices, ListAccountingConnections
invoice:sendSendInvoice
proforma:readGetProForma, ListProFormas
proforma:createCreateProForma
appointment:createCreateAppointment
appointment:readGetAppointment, ListAppointments, ListCustomerAppointments, ListAvailableAppointmentSlots, ListAgendas, ListAppointmentTypes, ListAgendaEligibleMembers, ListAppointmentResultCodes
appointment:updateUpdateAppointment
appointment:cancelCancelAppointment
appointment:record_resultRecordAppointmentResult
action_request:createCreateManualActionRequest
member:readListMembers, GetMember, SearchMembers, ListMemberInvitations
member_roles:updateReplaceMemberRoles
role:readListRoles, GetRole, SearchRoles
team:readListTeams, GetTeam, SearchTeams
team:createCreateTeam
member:inviteEmailMemberInvitation
member_invite_link:createCreateInviteLink
problem_template:readListProblemTemplates, GetProblemTemplate
problem_template:createCreateProblemTemplate
work_order_template:readListWorkOrderTemplates, GetWorkOrderTemplate, ListWorkOrderTemplateLocationFields
work_order_template:createCreateWorkOrderTemplate
work_order_template:updateUpdateWorkOrderTemplate
work_order_template:archiveArchiveWorkOrderTemplate
inventory:readSearchInventoryLocations, ListInventoryBalances, ListInventoryMovements, GetInventoryReceipt, GetOrderInventorySummary, ListOrderReservations, ListOrderStockDemand, LookupProductIdentifier, ListProductIdentifiers, ListInventoryTransfers, ListInventoryBackorders
inventory_location:createCreateInventoryLocation
inventory:adjustAdjustInventory
inventory:moveMoveInventory
inventory_receipt:createCreateInventoryReceipt
inventory_receipt:updateAddInventoryReceiptLine only; not general receipt editing
inventory_receipt:postReceiveInventory
inventory:reserveAllocateOrderStock, CreateOrderReservation, ReleaseReservation
inventory:consumeConsumeReservation
inventory:returnReturnInventory
inventory_identifier:writeAddProductIdentifier, DeleteProductIdentifier
inventory:transferStartInventoryTransfer, CompleteInventoryTransfer
inventory_backorder:writeCreateInventoryBackorder, UpdateInventoryBackorderEta
team:updateUpdateTeam
team_member:addAddTeamMember
team_member:removeRemoveTeamMember
role:createCreateRole
role:updateUpdateRole
member_invitation:revokeRevokeMemberInvitation
email_template:readListEmailTemplates, GetEmailTemplate
email_template:createCreateEmailTemplate (unpublished plain-text draft)
document_template:readListDocumentTemplates, GetDocumentTemplate
document_template:createCreateDocumentTemplate (blank PDF draft)
advanced_task_definition:readListAdvancedTaskDefinitions, GetAdvancedTaskDefinition
workflow_automation:readListWorkflowAutomations, GetWorkflowAutomation
journey:readListJourneyConfig
journey:writeSetCustomerJourneyStatus, ClearCustomerJourneyStatus
contact:readGetContact, ListContacts
contact:createCreateContact
contact:writeUpdateContact

API keys are creator-bound. Requests use the creating account’s current workspace membership, resource authorization, and delegation rights in addition to the key scopes. A scope cannot grant access the creator does not have.

Create separate named keys for separate clients or duties so each can be expired, restricted, or revoked independently.

CreateProblem and CreateWorkOrder use the same creation scopes for both general/direct and template-backed requests. Template discovery and authoring have separate scopes. Inventory receipt creation, adding lines, and posting also have separate scopes: only posting changes stock.

Actor permissions are separate from API-key scopes. Search requires the corresponding workspace read permission and applicable resource access. Product search accepts settings or inventory read access. Problem-template discovery uses content-template read access; work-order-template discovery accepts content-template or settings read access. Both template authoring operations require settings write access. Work-order preparation also requires readable customer data and only returns populated locations in the current Customer View. Problem/work-order creation needs the corresponding write capability and customer write access when linked to a customer. Both template-backed creation paths additionally require content-template read access, independently of discovery.

ContentTemplate email/document/advanced-task-definition reads require settings read access, not merely operational content-template access. Email and document draft creation requires settings write access. Neither scope grants draft editing, publication, sending, or document generation.

Directory role grants are administrative, not effective Customer View claims. Delegation checks apply to both existing and requested grants; system/owner role updates and removal of the last owner remain protected. See Manage Roles.

Use the exact scopes exposed in API-key settings and the tools advertised by tools/list. Wildcard access does not implicitly expose MCP tools. Missing credentials, missing exact scopes, disabled MCP, and denied resource IDs are distinct diagnostic cases; the Bruno collection includes them.

API keys can be restricted to specific IP addresses or CIDR ranges. If a key has no allowed CIDRs, it can be used from any IP.

If HeyX cannot start processing a request within 30 seconds, it returns a retryable timeout response. If processing has already started but the HTTP request times out, the operation may still continue in the background. Never assume a timeout cancelled a mutation, and do not blindly retry non-idempotent operations.