Keys

How a business issues, rotates and revokes the key your integration uses.

Every integration needs two things from the business: its business ID and a key secret. Keys are issued by the business, never by you.

Getting a key

  1. In Pairly, the business owner opens Settings → Integrations and finds the Webhook keys card.
  2. They create a key with a label naming your integration, for example "Acme signup form".
  3. Pairly shows the secret once. Copy it straight into your integration's secret store.
  4. The same dialog shows the receive URL, https://api.pairlyhq.com/v1/crm/webhooks/<business_id>/events. The business ID is the path segment after webhooks/.

Rotating and revoking

  • Rotate issues a new secret for the same key and stops the old secret immediately.
  • Revoke disables the key immediately and cannot be undone from the app. The business creates a new key instead.
  • Neither notifies you. If requests start failing with 401, ask the business whether the key was rotated or revoked.

More than one key

A business can hold several keys, one per integration. Each key has an id. On webhook requests you may send it as X-Pairly-Key-Id so Pairly checks only that key; without it, Pairly tries every active key on the business. A key from another business never verifies.