How to Generate and Use API Keys to Integrate with Other Systems

Vitor

Vitor

Last updated on Oct 7, 2026

To integrate your account with external systems like CRMs, ERPs, or automation platforms (n8n, Zapier), Papo (https://papo.global/) offers API (Application Programming Interface) keys that can be generated and managed directly in your dashboard. These keys function as secure credentials that authorize other software to programmatically access and perform actions in your Papo account.

Papo's API allows you to build connected work ecosystems, automating tasks ranging from sending WhatsApp messages to extracting qualified leads. To ensure security, Papo uses a two-key system: a public key for identification, and a secret key for authentication.

Key Type Description Security Level Example Usage
Public Key (pk_live_...) A unique and fixed identifier for your Papo account. Low. Can be exposed publicly. Identify your account in a script on your website's frontend.
Secret Key (sk_live_...) An API "password". Authenticates your requests and grants permission to act on behalf of your account. High. Must be kept strictly confidential. Authenticate an API call from your server (backend) to send a message.

How to Generate and Find Your API Keys

API keys are managed in a specific area of your Papo account. Follow the steps below to access them.

  1. Access your Papo dashboard and navigate to Settings.
  2. In the settings menu, look for the Developers or API section.
  3. On this page, you will find your Public Key (pk_live_...), which is fixed and can be copied at any time.
  4. For the Secret Key, you will need to generate a new one. Click the button to create a new key.
  5. Give the key a descriptive name, indicating where it will be used (e.g., "CRM Integration", "N8N Automation"). This helps identify and revoke specific keys if necessary.
  6. After creation, the Secret Key (sk_live_...) will be displayed only once. Copy it and store it in a secure location, such as a password manager or an environment variable on your server. For security reasons, Papo does not store the original key value and cannot display it again.

If you lose a secret key or suspect it has been leaked, revoke it immediately in the dashboard and create a new one.

How to Use the Keys to Authenticate with the API

All communication with Papo's API that involves actions or access to private data must be authenticated. This is done by sending the secret key in an HTTP header.

The base URL for all API calls is: https://app.papo.global/api/v1

To authenticate, include your secret key in the Authorization header of your request, preceded by the word Bearer.

Example curl request to get your account data:

curl https://app.papo.global/api/v1/me \
  -H "Authorization: Bearer YOUR_SECRET_KEY_HERE"

In this example:

  • sk_live_YOUR_SECRET_KEY_HERE must be replaced with your actual secret key.
  • The /me endpoint returns information about the authenticated account, serving as a good test to verify if your key is working.

The public key (pk_live_...) can optionally be sent in the X-Papo-Public-Key header as an additional verification, but the primary authentication is always done by the secret key.

What Can You Do with Papo's API?

The API opens up a range of possibilities for automating and integrating your operations. Here are some examples of what you can do:

  • Send WhatsApp messages: Create scripts to send notifications, alerts, or transactional messages through one of your connected numbers.
  • Fetch contacts from the Extractor: Access the list of leads you extracted with the CNPJ Extractor to synchronize them with your main CRM.
  • Manage instances: List and check the status of your WhatsApp connections.
  • Use Artificial Intelligence: Send texts to Papo's AI engine and receive generated responses based on your configured prompts.
  • Synchronize data: Keep your internal systems (ERP, BI) updated with the data generated in Papo.

Frequently Asked Questions (FAQ)

Where can I find the complete API documentation?

Detailed technical documentation, with all endpoints, parameters, and code examples in different languages (JavaScript, Python), is publicly available at papo.global/pt/docs.

My secret key was leaked. What should I do?

If you suspect your secret key has been compromised, immediately access the developers area in your Papo dashboard, find the leaked key in the list, and click to revoke it. Once revoked, it can no longer be used to authenticate requests. Then, generate a new key to replace the old one in your integrations.

How many secret keys can I create?

You can create multiple secret keys. It is good security practice to generate a different key for each system or environment you integrate (e.g., one for your CRM, another for your automation system, one for the testing environment, etc.). This allows you to revoke access for a specific system without affecting the others.

Can I use the public key on my website's frontend?

Yes, the public key (pk_live_...) is designed to be safe for use in public environments, such as your website's JavaScript code. Its function is only to identify your account, not to authenticate actions. The secret key, on the other hand, should never be exposed in client-side code.

What's the difference between Papo's API and a Webhook?

The main difference lies in who initiates the communication. With the API, your system initiates the action: you "request" (pull) data from Papo or "tell" (push) Papo to do something, like send a message. With a Webhook, Papo initiates the action: it "pushes" data to your system automatically when a specific event occurs (e.g., a contact reaches a stage in a Flow).

What's the difference between Papo's API and the Official WhatsApp API?

The Official WhatsApp API focuses exclusively on WhatsApp channel functionalities. Papo's API is a broader and more powerful abstraction layer: it allows you to control not only WhatsApp but also other platform modules, such as the CRM, the Lead Extractor, and the Artificial Intelligence engine, all with a single set of keys and in a simplified way.

Read also


Start integrating for free →

The first user is free for you to test automations and integrations with your number.