Authentication

Every request carries an API key. Sub-account keys are scoped to one sub-account; agency keys manage all of an agency's sub-accounts.

Key types

KeyPrefixCreated inScope
Sub-account keycfy_The sub-account: Settings → API & Webhooks → APIOne sub-account. Every read and write is confined to it; the request body can never select another tenant.
Agency keycfy_The agency workspace: Settings → API Keys (Agency API Keys card)The agency’s sub-accounts. Cannot call sub-account endpoints, and a sub-account key cannot call agency endpoints.

Keys are secrets. Never put them in client-side code you don’t control, and rotate any key you suspect has leaked.

Sending the key

Either header works on every endpoint:

curl "https://api.centerfy.ai/webhooks/inbound/tags" -H "x-api-key: cfy_…"
# or
curl "https://api.centerfy.ai/webhooks/inbound/tags" -H "Authorization: Bearer cfy_…"

Plan requirement

API access is part of the White Label and SaaS Mode plans. On any other plan every request, with a valid key, returns:

{ "status": "error", "error": "API access is not enabled for this account. Upgrade to a White Label or SaaS Mode plan to use the API." }

with HTTP status 403.

Errors you’ll see

StatusMeaning
401No key sent, or the key is unknown or revoked.
403The key is valid but the plan has no API access, or you used the wrong key type for this endpoint (sub-account vs agency).
© 2026 Centerfy AI. All rights reserved.