Authentication
Every request carries an API key. Sub-account keys are scoped to one sub-account; agency keys manage all of an agency's sub-accounts.
Key types
| Key | Prefix | Created in | Scope |
|---|---|---|---|
| Sub-account key | cfy_ | The sub-account: Settings → API & Webhooks → API | One sub-account. Every read and write is confined to it; the request body can never select another tenant. |
| Agency key | cfy_ | The agency workspace: Settings → API Keys (Agency API Keys card) | The agency’s sub-accounts. Cannot call sub-account endpoints, and a sub-account key cannot call agency endpoints. |
Keys are secrets. Never put them in client-side code you don’t control, and rotate any key you suspect has leaked.
Sending the key
Either header works on every endpoint:
curl "https://api.centerfy.ai/webhooks/inbound/tags" -H "x-api-key: cfy_…"
# or
curl "https://api.centerfy.ai/webhooks/inbound/tags" -H "Authorization: Bearer cfy_…"
Plan requirement
API access is part of the White Label and SaaS Mode plans. On any other plan every request, with a valid key, returns:
{ "status": "error", "error": "API access is not enabled for this account. Upgrade to a White Label or SaaS Mode plan to use the API." }
with HTTP status 403.
Errors you’ll see
| Status | Meaning |
|---|---|
401 | No key sent, or the key is unknown or revoked. |
403 | The key is valid but the plan has no API access, or you used the wrong key type for this endpoint (sub-account vs agency). |