Authentication
All EmacronAI CRM API requests are authenticated using a Bearer token in the HTTP Authorization header. Your API key is the token.
Getting your API key
- 1Sign up for EmacronAI CRM (free, no credit card)
- 2Go to Settings → API Keys
- 3Click Create API Key, give it a name, and copy it
- 4Store it in your environment as
OUTREACHAGENT_API_KEY
Using your API key
Include the Authorization header in every request:
Authorization: Bearer YOUR_API_KEYcURL
curl https://api.crm.emacronai.com/v1/otp/send \
-H "Authorization: Bearer $OUTREACHAGENT_API_KEY" \
-H "Content-Type: application/json" \
-d '{"phone": "+919876543210"}'Node.js (SDK)
import { createClient } from '@emacrontechnologies/outreachagent';
// Reads process.env.OUTREACHAGENT_API_KEY automatically
const oa = createClient(process.env.OUTREACHAGENT_API_KEY);Environment best practices
✓Store key in environment variable: OUTREACHAGENT_API_KEY=...
✓Add .env to .gitignore to prevent accidental commits
✓Use separate keys for development and production
✕Never hardcode keys in source code
✕Never commit keys to git or expose in client-side JS
✕Never share keys in Slack, email, or screenshots
API key scopes
| Scope | Allows |
|---|---|
| whatsapp:send | Send OTPs, broadcast messages, template messages |
| contacts:write | Create, update, and delete contacts |
| contacts:read | Read contact data and segments |
| webhooks:manage | Register and delete webhook endpoints |
| analytics:read | Read campaign and CTwA analytics |
Authentication errors
| Code | Name | Cause | Fix |
|---|---|---|---|
| 401 | Unauthorized | Missing or invalid API key | Check Authorization header is present and formatted as "Bearer API_KEY" |
| 403 | Forbidden | Key has insufficient permissions | Check key scopes in Settings → API Keys |
| 429 | Too Many Requests | Rate limit exceeded | Respect Retry-After header; implement exponential backoff |