When you need an API key
An API key lets your own systems talk to Majarrah without a browser session — sync inventory from your CRM, push new projects from your ERP, mirror leads into HubSpot / Salesforce. You don’t need a key for:- Rendering the widget (the widget uses a public
data-developerslug) - Team members logging into the dashboard (they use their own account)
- Programmatic listing creates/updates
- Pulling leads out into your own CRM
- Custom AI Decision integrations
- Any server-side automation
Create a key
1
Open Settings → API Keys
From your dashboard sidebar.
2
Click Create key
Give it a label (e.g.
crm-sync-prod) so you know where it’s used.3
Copy the secret
The secret is shown once. Store it in your secret manager immediately. You cannot recover it later.
Use it
Every API request includes the key in theAuthorization header:
Rotate or revoke
Every key on your list has a Rotate and Revoke action:- Rotate issues a fresh secret and gives you a 24-hour grace window where both old and new work. Use it to swap keys without downtime.
- Revoke invalidates the key immediately. Use it if you suspect a secret was leaked.
Key hygiene
Never commit an API key to source control. Never share one over email or chat. If a key was ever exposed publicly — even briefly — revoke and rotate it immediately.