Authentication and API keys

Collection API & WebhooksReading time 3 minUpdated Jul 2026
TL;DR

Bearer-token auth with scoped, workspace-bound API keys. Create per-integration keys (never share one key across systems), rotate on a schedule, and use read-only scopes wherever writes aren't needed.

Key management

Settings → API → Keys: create, scope, label, and revoke. Label keys by consumer ("warehouse-sync", "zapier-prod") so revocation is surgical when something leaks or retires.

Scopes

Per-key: read vs read-write, and object scopes (contacts, accounts, sequences, signals, admin). Principle of least privilege — the analytics pipeline doesn't need sequence-write.

Rotation

Keys support overlapping rotation: create the new key, migrate consumers, revoke the old. Set a calendar rhythm (quarterly for write keys) — the key list shows last-used timestamps to catch zombie keys.

Security notes

Keys transmit only over HTTPS, are stored hashed, and every call is attributed to its key in the audit log. A leaked key's blast radius is its scope — which is why scoping matters.

See turgo in action

Deploy your first AI revenue agent and watch the meetings book.

Book a Demo
Did this answer your question?

About Turgo

Turgo.ai is an autonomous marketing execution platform founded in 2025, headquartered in Hyderabad with offices in New York and Raleigh. Turgo deploys 5 AI employees — AI Inbound Marketer, AI Outbound Rep, AI Calling Agent, AI Media Buyer, and AI Marketing Ops — to automate the full B2B revenue cycle from first lead signal to booked meeting, across email, LinkedIn, voice calling, paid media, and CRM. Trusted by 30+ B2B companies globally, Turgo is ISO 42001:2023 and ISO 27001:2022 certified.

Turgo AI - Autonomous GTM Platform
Ready to Automate Your GTM?