REST API
Build on Pitch2Sale with personal access tokens for your own scripts, and OAuth apps for tools that act on a user's behalf. Every request runs with that user's permissions, so the API never sees more than they could.
Scoped token in, the user's view out
Your script sends a token with each request. Pitch2Sale checks the token's scopes and its user's role, then answers with only what that user may see.
GET /api/v1/leads
Reporting sync
- 01Create a token in Settings and tick only the scopes it needs.
- 02Your script sends it as a Bearer token.
- 03Pitch2Sale checks the scope, then the user's role permissions.
- 04The response holds only records that user can see.
- 05The token's Last used time updates, and you can revoke it in one click.
What it does in Pitch2Sale
Scoped access
Twelve read and write scopes across leads, contacts, opportunities, invoices, proposals and projects.
Acts as its user
A token carries its user's role, so it never sees more than they would.
For other tools
OAuth 2.0 with PKCE and refresh tokens, and a consent screen for the user.
Last used and revoke
See when each token was last used and revoke it instantly.
Set it up
- Open Settings → Developer → API Keys.
Admins can create tokens and apps by default.
- Click New Key.
Give the token a Label.
- Untick the scopes it does not need.
All scopes start ticked.
- Click Create token and copy it.
It is shown once.
- For an OAuth app, click New App.
Enter the app name, an optional description and redirect URIs, one per line, then pick scopes and click Create.
- Call the API.
Send the token as
Authorization: Bearer …. The developer docs list every endpoint.
What syncs, and what does not
| Direction | What | When |
|---|---|---|
| Your tool → Pitch2Sale | Reads and writes on leads, contacts, opportunities, invoices and proposals, within the token's scopes | Each request |
| Pitch2Sale → your tool | JSON responses limited to what the token's user can see | Each request |
| Pitch2Sale → your tool | OAuth access tokens (one hour) and refresh tokens | When a user approves your app |
| Not synced | Nothing is pushed by the API itself; use outbound webhooks for events | — |
Common questions
Do tokens expire?
Personal access tokens last until you revoke them. OAuth access tokens last an hour and refresh.
I lost my token.
It is shown only once. Revoke it and create a new one.
Is there a rate limit?
Yes, 300 requests a minute from one address.
Can I get events instead of polling?
Yes, with outbound webhooks.
Build on the same record your team uses.
Create a scoped token in Settings and make your first call in minutes.