Reach API: keys, scopes, and workspaces

Set up a server-to-server connection using Reach’s actual API controls.

Open this guide in the help center →

When to use this. A website or backend needs to send leads to Reach without depending on a user’s browser session.

What you’ll need. Access to Settings → API Access in the intended Reach workspace and a server-side secret store.

  1. Open the right workspace

    Open Reach → Settings → API Access. Each key belongs to one workspace; resources created with it stay in that workspace.

  2. Choose access deliberately

    Create a key with only the scopes required by the integration. The page supports expiry, last-use tracking, and revocation. The secret is shown once and stored as a hash; save it securely at creation.

  3. Authenticate on the server

    Send Authorization: Bearer with the key. The signed-in settings page also documents x-api-key. Never put the secret in browser JavaScript, an embed, or a public help article.

  4. Make a small read request

    Use prospects.read to list prospects with page and limit. Check Recent API usage for the key, endpoint, status, and response time.

How to know it worked

A read request succeeds with the intended workspace key and the integration has only the access it needs.

Features covered

Continue learning