Skip to main content
Most Aptly API endpoints accept an API key. Some endpoints also accept delegate tokens or partner bearer tokens, and explicitly public endpoints require no credential. Check each operation in the API Reference for its supported methods.

API keys

API keys are created per company and work across all boards. A key must belong to a company that has the API enabled on the board being accessed. To create a key:
  1. Open the board in Aptly
  2. Go to Card Sources → API
  3. Toggle the API on
  4. Click Create New Key, enter a name, and optionally set an expiration date
  5. Copy the key — it won’t be shown again

Passing the key

Always pass API keys in the x-token header. Query-string credentials can be captured in server logs, browser history, and referrer headers.
Core API and Portal API use different authentication schemes.The Core API uses a static API key passed as an x-token header or query parameter. Everything on this page applies to the Core API only.The Portal API (https://app.getaptly.com/api/portal) uses JWT-based authentication scoped to a contact session. If you are building against the Portal API, refer to the Contact Verification & Lightweight SSO guide for how to obtain and pass a token.

Error responses

Key expiration

Keys can be created with or without an expiration date. Keys without an expiration remain active until archived. Expired or archived keys return 401.