> For the complete documentation index, see [llms.txt](https://docs.reach-book.com/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://docs.reach-book.com/integrations/api-and-webhooks.md).

# API tokens and webhooks

Administrators open **Workspace settings → Automation & API**. Full reference: [reach-book.com/developers](https://reach-book.com/developers), with Zapier and Make guides.

![Automation & API with webhooks, tokens and delivery activity](https://965745608-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2Fdg7LyestsaNAIIzzILlv%2Fuploads%2Fgit-blob-1daf5b3ab278fdc340147ebc2bb3a1eda78e8d76%2Fautomation.webp?alt=media)

## API tokens

Click **Create token** and choose only the abilities it needs:

* Read prospects and groups
* Create and update prospects and groups
* Delete prospects
* Update prospect outcomes
* Read campaigns and their results
* Add prospects to draft campaigns, pause and resume campaigns
* Read the do-not-contact list
* Add to and remove from the do-not-contact list
* Read workspace members

The API can add prospects to a draft campaign, but it can't launch one. Launching is always reviewed in the app. Campaign abilities only reach the campaigns of the person who created the token.

Abilities can't be changed later. A token must expire within one year, is shown only once and starts with `rbk_`. It stops working if the person who created it loses admin access. The API allows 60 requests per minute.

## Webhooks

Click **Add webhook** and pick the events:

* Prospect created
* Prospect outcome updated
* Reply received
* Conversation assigned
* Opportunity updated
* Meeting booked
* Opportunity won

Rules for the receiving address:

* HTTPS on port 443, with no query string. Redirects aren't followed.
* Your service must answer with a 2xx status within 10 seconds.

Each request is signed with HMAC-SHA256 in the `Reachbook-Timestamp` and `Reachbook-Signature` headers, so you can check it came from Reach-book.com. Failed deliveries are retried after 1 minute, 5 minutes, 30 minutes and 2 hours (5 attempts in total). The **Activity** tab shows every delivery.
