API Key Security and Inactivity Policies
To maintain a secure environment, your CRM automatically manages API keys that have been inactive for extended periods. This includes both the removal of unused keys and the expiration of older legacy keys.
Automatic Deletion of Inactive API Keys
API keys at the agency or sub-account level that have not been used for 90 days will be automatically deleted. This process runs once per quarter across all such keys.
Notifications are sent to keep you informed:
- In-app alerts are shown to impacted agency and sub-account administrators at 15 days, 7 days, and 1 day before deletion.
- Agency admins (including those with affected locations) receive an email 15 days prior with a summary of the upcoming deletions.
- A banner is displayed for 24 hours, starting one day before deletion, to all impacted agencies and sub-accounts.
Expiration of Inactive Legacy API Keys
Legacy API keys that are inactive for 90 days are marked as Expired. This reduces credential exposure and enhances account security. It applies to both agency-level and location-level legacy keys.
Important details:
- Active keys are not affected.
- Expired keys remain visible in your settings.
- If you need access again, you can rotate or refresh an expired key to make it active.
- Creation of new v1 API keys is no longer supported. Private Integration Tokens (PIT) are the recommended alternative for new credentials.
- You may receive email notifications when a legacy API key is nearing expiration due to inactivity.