Where to find your API key (integration tokens)

Where to find your API key

Commslayer API keys are called Integration tokens and can be found in your account settings. Only admins can create, rotate or revoke tokens.

Finding your token

  1. Click Settings in the left sidebar

  2. Go to Integration tokens

  3. Click on Create new token, enter the token name and select permissions. Once you are done, click on Create token

  4. Copy the token right away. It is shown only once.

  5. If you want to revoke the token, on the active one, click on Revoke

Tokens stop working after 90 days. Open a token's menu and click View details to see its Expires date. Before that date, create a new token, switch your integration to it, then click Revoke on the old one. Rotate gives you a new token but keeps the same expiry date. A token past its date shows as Expired.

What you can use the API key for

Your integration token lets your own scripts and systems read and change data in Commslayer through the API. The section "What you can do with the API" at the end of this article has the details.

You don't need a token to connect Claude or ChatGPT. The MCP connector asks you to sign in with your Commslayer account instead.

Keep your token safe

  • Treat your API key like a password. Don't share it publicly or commit it to code repositories.

  • If you believe your token has been compromised, click Rotate on it. This creates a new token and stops the old one from working, so update any integration that used it.

Need a different type of access?

You don't need a token to connect a store, a channel or a supported app:

  • Shopify stores are added under Settings → Shops.

  • Channels such as email, Meta, WhatsApp and Judge.me are added under Settings → Inboxes → Add inbox.

  • Subscription apps such as Recharge, Loop and Skio are connected under Settings → Integrations.

What you can do with the API

The API is included in every plan on our pricing page. Requests go to https://app.commslayer.com/api/integration/v1 with the header Authorization: Bearer <your token>. The full reference with request examples is in the API documentation. You can also open it with View API documentation on the Integration tokens page.

A token works in one Commslayer account. If you run several accounts, create a token in each.

Things to know

  • New conversations need an existing inbox and a contact. Pass the inbox_id of an inbox you already have, plus a contact_id or contact_email. Every conversation the API returns carries its inbox_id. Inboxes can't be listed or created through the API. In a WhatsApp inbox, the contact must already have a conversation there.

  • Email subject: pass subject when you create the conversation or send a message. Without it the recipient sees "[#N] New messages on this conversation".

  • Sender: messages sent through the API carry no agent name, and you can't set a sender name or avatar. To send as a person, reply in the app or through the MCP connector, where replies are sent as the person who connected it.

  • Labels on a conversation: the API can't add or remove them. Use the MCP connector, an automation rule, or a label with Apply automatically switched on.

  • Canned responses, macros and automations: not in the API. Manage them through the MCP connector.

  • Rate limit: 60 requests per minute per token. Above that you get a 429 response with a Retry-After header.

  • Lists: 25 results per page, 100 at most. Use the cursor in the response to get the next page.