
Xcellerate OPS has a documented REST API (v1). Use it to connect your own tools, scripts or automation platforms to tickets, companies, contacts, deals, projects, time entries, assets and more. Every user creates their own API keys from their profile, and a key can do exactly what that user can do in the app, no more. This guide is for technical admins at MSPs and service businesses.
TL;DR
- Create a key in your profile under API keys and copy the token straight away: it is shown only once.
- Send two headers with every request:
Authorization: Bearer <token>andX-Tenant-Id.- A key inherits your user's rights. The default limit is 120 requests per minute per key.
Before you start
- Any staff user can create keys for themselves. You do not need the admin role.
- What a key can do mirrors your team permissions one to one. Blocked in the app means blocked in the API.
- You need an HTTP client that can send headers: a script, an automation platform or your own application.
- You can have up to 20 active keys per user.
Note: the API keys section is English-only in the app, so the labels below are in English.
Create and use an API key
Step 1: Open your API keys
Go to your profile and open the API keys section.
Step 2: Create the key
Give the key a name that says what it is for. Choose whether it can only read or can also write, and optionally set an expiry date in the future. Keys are read-only unless you create them with write access. If you only need to read data, keep it read-only.
Step 3: Copy the token
After creating the key, OPS shows "Copy your new API key now — it will not be shown again." Copy the token immediately and keep it somewhere safe. Tokens start with xok_. If you lose it, create a new key.
Step 4: Copy your workspace ID
The same section shows your workspace ID (tenant id). Copy it with the Copy button. You need it on every request.
Step 5: Make a first call
Test your key with a simple request to /api/v1/me, sending both headers:
GET /api/v1/me
Authorization: Bearer <token>
X-Tenant-Id: <workspace id>
The API documentation ↗ link in the section opens the interactive documentation. Check the correct base address and the available endpoints there.
Step 6: Revoke keys you no longer use
You revoke a key from the same list. Each key shows when it was last used, which makes it easy to spot keys nobody needs any more.
What happens after you connect
- Format: JSON for requests and responses. Lists use cursor pagination.
- Coverage: including companies, contacts, CRM interactions, custom fields, tickets and ticket schedules, projects with planning and finance, time entries, expenses, absences, working time, assets and CMDB, software, services, changes, problems, major incidents, releases, knowledge base, opportunities, rate cards, recurring invoices, reports, SLA and XLA reports, calls and recordings, and the AI action log. The API documentation has the full list.
- Client portal: customers using your client portal can create their own keys there. Those keys only see their own data.
To learn how OPS protects access, see security and access control. All connections are listed under EU integrations and security.
Good to know
- Rate limit: 120 requests per minute per key by default. RMM Labs can raise it for a workspace on request. Every response carries the
X-RateLimit-LimitandX-RateLimit-Remainingheaders. - Failed sign-ins: repeated failed authentications from the same address are temporarily blocked.
- Keys belong to a person. Disabling a user revokes their keys and blocks them. Integrations running on those keys stop working, so plan for this when someone leaves.
- Personal settings, such as calendar sync preferences, are not available through the API.
Troubleshooting
- 401
unauthenticated"Invalid API credentials." The token is wrong, expired or revoked, theX-Tenant-Idis missing or wrong, the workspace is suspended or the user is disabled. All of these deliberately give the same answer. - 429
rate_limited"Too many requests." Wait the number of seconds in theRetry-Afterheader. - 429 "Too many failed authentication attempts." Your IP address is temporarily locked after repeated failures.
- "You have reached the maximum number of API keys." You have 20 active keys. Revoke one first.
Get started
Want to connect OPS to your own scripts and tools? Get started for free and create your first API key in your profile.

