API tokens
Tokens for lead-capture forms and the v1 REST API.
SettingsUpdated
Quick answer
Where do I rotate my API token?
Workspace owners create tokens here. A token with no scopes can only capture leads from forms on the sites you allow.
Add scopes to use the REST API: contacts:read (list and export contacts), campaigns:read (campaign recipients), segments:read and email:send (transactional email). Send the token in the Authorization: Bearer header — query-string tokens are refused — and expect a per-key rate limit. The API does not expose SEO data such as rankings or audits.