Skip to content
ClientTether Support
Integrations · Developer guide

API Overview

Authentication with two header keys, how GET and POST calls are built, and the one setting that stops create_client duplicating your contacts.

New · Updated Sep 21, 2026 · 5 min read
On this page

1What the API is for

ClientTether’s REST API lets your own systems create, read, update and delete most of what’s in an account — contacts, events, notes, action plans, lead sources, sales cycles, users, proposals and payments. Version 2.0 uses GET, POST and DELETE and answers with JSON; a request it doesn’t recognise comes back as an HTTP error before it reaches the API itself.

If all you want is to push web-form leads in, you don’t need the API — see Web Forms & the Web Key. If the source can only send email, see Email Parser.

2Access: two header keys

There’s no login step. Every call carries two headers, and together they decide what you can reach:

HeaderWhat it doesWhere to get it
X-Access-TokenGrants access. It encodes the username, user level and white-label id, so changing that account information regenerates the token automatically.Settings → API, at the Enterprise level only.
X-Web-KeyIdentifies which account you’re acting on. One Enterprise token works across the tree; the web key picks the account.Each account’s own Settings → API tab, or by API call for sub-accounts.

Both go in the header of every request. Without them the call fails at the server and never reaches the API.

These tokens are account access. Anyone holding them can read and delete your contacts. Never share them outside your organisation and development team, never commit them to a public repository, and never put them in front-end code a browser can read.

3Building a GET call

Two shapes, depending on the request:

  • Query string — base URL, request name, ?, then parameters:
    https://api.clienttether.com/v2/api/read_client_exist?phone=3039291447
  • Path parameter — base URL, request name, /, then the id:
    https://api.clienttether.com/v2/api/read_client_by_id/1234

4Building a POST call

Because access travels in headers, a REST POST here isn’t built like a web-form POST. Parameters are key:value pairs in the body of the request; which keys you need depends on the request. The keys themselves are listed in API Parameters Reference, and each request’s required keys in API Endpoint Reference.

5Testing it

ClientTether publishes a Postman collection with every endpoint and example requests, so you can try calls before writing any code. Ask your Success Manager for the current collection link, and use your own tokens — pasting the sample tokens from the documentation is the mistake almost every developer makes first.

Duplicate checking on create_client

create_client only checks for duplicates when the account has that setting switched on in Settings → API. It’s off by default, and cloned and sub-accounts inherit it off. Turn it on unless you’re deliberately handling duplicates yourself.

6Troubleshooting

Every call returns an error before reaching the API

A header is missing or wrong. Check both, and check you’re using your own tokens.

Calls succeed but touch the wrong account

The X-Web-Key belongs to another account in the tree.

The token stopped working

Account information behind it changed, which regenerates it. Copy the current one from Settings → API.