REST API

Build on Pitch2Sale with personal access tokens for your own scripts, and OAuth apps for tools that act on a user's behalf. Every request runs with that user's permissions, so the API never sees more than they could.

CategoryDeveloper
Data flowTwo-way
SetupBuilt in
PlansEvery plan
How a request moves

Scoped token in, the user's view out

Your script sends a token with each request. Pitch2Sale checks the token's scopes and its user's role, then answers with only what that user may see.

Your script

GET /api/v1/leads

Tokenpat_1a2b…
Scopesread:leads
200 OK
Pitch2Sale · Personal access token CreatedLast used

Reporting sync

OwnerNina Alvarez
Scopesread:leads, read:invoices
Last usedjust now
  1. 01Create a token in Settings and tick only the scopes it needs.
  2. 02Your script sends it as a Bearer token.
  3. 03Pitch2Sale checks the scope, then the user's role permissions.
  4. 04The response holds only records that user can see.
  5. 05The token's Last used time updates, and you can revoke it in one click.

What it does in Pitch2Sale

01 · Tokens

Scoped access

Twelve read and write scopes across leads, contacts, opportunities, invoices, proposals and projects.

02 · Permissions

Acts as its user

A token carries its user's role, so it never sees more than they would.

03 · OAuth apps

For other tools

OAuth 2.0 with PKCE and refresh tokens, and a consent screen for the user.

04 · Control

Last used and revoke

See when each token was last used and revoke it instantly.

Set it up

  1. Open Settings → Developer → API Keys.

    Admins can create tokens and apps by default.

  2. Click New Key.

    Give the token a Label.

  3. Untick the scopes it does not need.

    All scopes start ticked.

  4. Click Create token and copy it.

    It is shown once.

  5. For an OAuth app, click New App.

    Enter the app name, an optional description and redirect URIs, one per line, then pick scopes and click Create.

  6. Call the API.

    Send the token as Authorization: Bearer …. The developer docs list every endpoint.

What syncs, and what does not

DirectionWhatWhen
Your tool → Pitch2SaleReads and writes on leads, contacts, opportunities, invoices and proposals, within the token's scopesEach request
Pitch2Sale → your toolJSON responses limited to what the token's user can seeEach request
Pitch2Sale → your toolOAuth access tokens (one hour) and refresh tokensWhen a user approves your app
Not syncedNothing is pushed by the API itself; use outbound webhooks for events—

Common questions

Do tokens expire?

Personal access tokens last until you revoke them. OAuth access tokens last an hour and refresh.

I lost my token.

It is shown only once. Revoke it and create a new one.

Is there a rate limit?

Yes, 300 requests a minute from one address.

Can I get events instead of polling?

Yes, with outbound webhooks.

Build on the same record your team uses.

Create a scoped token in Settings and make your first call in minutes.