Reach API: keys, scopes, and workspaces
Set up a server-to-server connection using Reach’s actual API controls.
Open this guide in the help center →
When to use this. A website or backend needs to send leads to Reach without depending on a user’s browser session.
What you’ll need. Access to Settings → API Access in the intended Reach workspace and a server-side secret store.
Open the right workspace
Open Reach → Settings → API Access. Each key belongs to one workspace; resources created with it stay in that workspace.
Choose access deliberately
Create a key with only the scopes required by the integration. The page supports expiry, last-use tracking, and revocation. The secret is shown once and stored as a hash; save it securely at creation.
Authenticate on the server
Send Authorization: Bearer with the key. The signed-in settings page also documents x-api-key. Never put the secret in browser JavaScript, an embed, or a public help article.
Make a small read request
Use prospects.read to list prospects with page and limit. Check Recent API usage for the key, endpoint, status, and response time.
How to know it worked
A read request succeeds with the intended workspace key and the integration has only the access it needs.
Features covered
- Workspace-scoped API keys
- Per-key scopes and expiry
- Recent API usage