API Overview
Authentication with two header keys, how GET and POST calls are built, and the one setting that stops create_client duplicating your contacts.
On this page
1What the API is for
ClientTether’s REST API lets your own systems create, read, update and delete most of what’s in an account — contacts, events, notes, action plans, lead sources, sales cycles, users, proposals and payments. Version 2.0 uses GET, POST and DELETE and answers with JSON; a request it doesn’t recognise comes back as an HTTP error before it reaches the API itself.
If all you want is to push web-form leads in, you don’t need the API — see Web Forms & the Web Key. If the source can only send email, see Email Parser.
2Access: two header keys
There’s no login step. Every call carries two headers, and together they decide what you can reach:
| Header | What it does | Where to get it |
|---|---|---|
X-Access-Token | Grants access. It encodes the username, user level and white-label id, so changing that account information regenerates the token automatically. | Settings → API, at the Enterprise level only. |
X-Web-Key | Identifies which account you’re acting on. One Enterprise token works across the tree; the web key picks the account. | Each account’s own Settings → API tab, or by API call for sub-accounts. |
Both go in the header of every request. Without them the call fails at the server and never reaches the API.
These tokens are account access. Anyone holding them can read and delete your contacts. Never share them outside your organisation and development team, never commit them to a public repository, and never put them in front-end code a browser can read.
3Building a GET call
Two shapes, depending on the request:
- Query string — base URL, request name,
?, then parameters:https://api.clienttether.com/v2/api/read_client_exist?phone=3039291447 - Path parameter — base URL, request name,
/, then the id:https://api.clienttether.com/v2/api/read_client_by_id/1234
4Building a POST call
Because access travels in headers, a REST POST here isn’t built like a web-form POST. Parameters are key:value pairs in the body of the request; which keys you need depends on the request. The keys themselves are listed in API Parameters Reference, and each request’s required keys in API Endpoint Reference.
5Testing it
ClientTether publishes a Postman collection with every endpoint and example requests, so you can try calls before writing any code. Ask your Success Manager for the current collection link, and use your own tokens — pasting the sample tokens from the documentation is the mistake almost every developer makes first.
Duplicate checking on create_client
create_client only checks for duplicates when the account has that setting switched on in Settings → API. It’s off by default, and cloned and sub-accounts inherit it off. Turn it on unless you’re deliberately handling duplicates yourself.
6Troubleshooting
Every call returns an error before reaching the API
A header is missing or wrong. Check both, and check you’re using your own tokens.
Calls succeed but touch the wrong account
The X-Web-Key belongs to another account in the tree.
The token stopped working
Account information behind it changed, which regenerates it. Copy the current one from Settings → API.
7Related pages
- API Endpoint Reference, API Parameters Reference.
- Integrations Overview — the API Monitor.