Skip to main content
Bold accepts two API authentication methods: API keys for server-to-server integrations and session credentials for users.
If the request includes the X-Api-Key header, Bold uses API key authentication. Otherwise, it validates the request as a user session.

Get an API key

You must be an administrator to create or disable API keys. In the app, you manage them in Control panel > Access > API keys.
1

Open API keys

Go to Control panel and open API keys in the Access group.
2

Create a key

Click Create new API key. Enter a value in Key name, such as Production management or Inventory analysis.
3

Save the secret

Click Create key and copy the value shown in API key created. The full key is only displayed at this point.
4

Confirm you have copied it

Save the key in your integration’s secret manager and confirm with I have copied and saved it.

Use API keys

Use API keys for technical integrations. The key identifies the organization and is a secret credential. Send it in the X-Api-Key header.
Good practices:
  • Create a key for each external system.
  • Use descriptive names such as Production management or Inventory analysis.
  • Rotate the key if you suspect it was shared outside the authorized system.
  • Revoke keys that are no longer used.
Do not store API keys in repositories, shared documents, or local scripts without a secret manager.

Session credentials

Use session credentials when a request represents an interactive user session.
The credential must include the organization context and the required permissions. If it expires or belongs to a different organization, the API returns an authentication or authorization error.

Permissions

Authentication answers “who is calling”. Permissions answer “what they can do”.

Example

Start with a read endpoint and a small page size. Add write operations after you confirm that the key belongs to the correct organization.

Manage keys

Create, view, and disable keys in Control panel > Access > API keys. See Integration keys and external notifications to understand how keys and external notifications are managed.