RMM Labs
Integrations 4 min read 28 September 2026 By Fred

Using the Xcellerate OPS REST API with personal API keys

Create a personal API key in your profile and connect your own tools to Xcellerate OPS. How the REST API works, with headers, limits and troubleshooting.

Xcellerate OPS has a documented REST API (v1). Use it to connect your own tools, scripts or automation platforms to tickets, companies, contacts, deals, projects, time entries, assets and more. Every user creates their own API keys from their profile, and a key can do exactly what that user can do in the app, no more. This guide is for technical admins at MSPs and service businesses.

TL;DR

  • Create a key in your profile under API keys and copy the token straight away: it is shown only once.
  • Send two headers with every request: Authorization: Bearer <token> and X-Tenant-Id.
  • A key inherits your user's rights. The default limit is 120 requests per minute per key.

Before you start

  • Any staff user can create keys for themselves. You do not need the admin role.
  • What a key can do mirrors your team permissions one to one. Blocked in the app means blocked in the API.
  • You need an HTTP client that can send headers: a script, an automation platform or your own application.
  • You can have up to 20 active keys per user.

Note: the API keys section is English-only in the app, so the labels below are in English.

Create and use an API key

Step 1: Open your API keys

Go to your profile and open the API keys section.

Step 2: Create the key

Give the key a name that says what it is for. Choose whether it can only read or can also write, and optionally set an expiry date in the future. Keys are read-only unless you create them with write access. If you only need to read data, keep it read-only.

Step 3: Copy the token

After creating the key, OPS shows "Copy your new API key now — it will not be shown again." Copy the token immediately and keep it somewhere safe. Tokens start with xok_. If you lose it, create a new key.

Step 4: Copy your workspace ID

The same section shows your workspace ID (tenant id). Copy it with the Copy button. You need it on every request.

Step 5: Make a first call

Test your key with a simple request to /api/v1/me, sending both headers:

GET /api/v1/me
Authorization: Bearer <token>
X-Tenant-Id: <workspace id>

The API documentation ↗ link in the section opens the interactive documentation. Check the correct base address and the available endpoints there.

Step 6: Revoke keys you no longer use

You revoke a key from the same list. Each key shows when it was last used, which makes it easy to spot keys nobody needs any more.

What happens after you connect

  • Format: JSON for requests and responses. Lists use cursor pagination.
  • Coverage: including companies, contacts, CRM interactions, custom fields, tickets and ticket schedules, projects with planning and finance, time entries, expenses, absences, working time, assets and CMDB, software, services, changes, problems, major incidents, releases, knowledge base, opportunities, rate cards, recurring invoices, reports, SLA and XLA reports, calls and recordings, and the AI action log. The API documentation has the full list.
  • Client portal: customers using your client portal can create their own keys there. Those keys only see their own data.

To learn how OPS protects access, see security and access control. All connections are listed under EU integrations and security.

Good to know

  • Rate limit: 120 requests per minute per key by default. RMM Labs can raise it for a workspace on request. Every response carries the X-RateLimit-Limit and X-RateLimit-Remaining headers.
  • Failed sign-ins: repeated failed authentications from the same address are temporarily blocked.
  • Keys belong to a person. Disabling a user revokes their keys and blocks them. Integrations running on those keys stop working, so plan for this when someone leaves.
  • Personal settings, such as calendar sync preferences, are not available through the API.

Troubleshooting

  • 401 unauthenticated "Invalid API credentials." The token is wrong, expired or revoked, the X-Tenant-Id is missing or wrong, the workspace is suspended or the user is disabled. All of these deliberately give the same answer.
  • 429 rate_limited "Too many requests." Wait the number of seconds in the Retry-After header.
  • 429 "Too many failed authentication attempts." Your IP address is temporarily locked after repeated failures.
  • "You have reached the maximum number of API keys." You have 20 active keys. Revoke one first.

Get started

Want to connect OPS to your own scripts and tools? Get started for free and create your first API key in your profile.

Frequently asked questions

What can an API key access?
Exactly what the user who created it can access, based on their team permissions. A key is read-only unless you create it with write access.
How many requests can I make?
By default 120 requests per minute per key. RMM Labs can raise that limit for a workspace on request.
What happens to a leaver's API keys?
When you disable the user, their keys are revoked and blocked. Integrations that use those keys stop working.
Sources: Verified against the Xcellerate OPS source code by the product team on 2026-09-28. Feature pages: https://rmmlabs.io/en/products/ops/features/integrations-eu; https://rmmlabs.io/en/products/ops/features/security-access.

Ready to solve time registration compliance?

Xcellerate OPS covers Belgian 2027 time registration requirements out of the box — no extra module needed.

Related articles