API tokens and webhooks
API tokens and webhooks
Administrators open Workspace settings → Automation & API. Full reference: reach-book.com/developers, with Zapier and Make guides.
API tokens
Click Create token and choose its abilities:
- Read prospects
- Create prospects
- Update prospect outcomes
Abilities can't be changed later. A token must expire within one year, is shown only once and starts with rbk_. It stops working if the person who created it loses admin access. The API allows 60 requests per minute.
Webhooks
Click Add webhook and pick the events:
- Prospect created
- Prospect outcome updated
- Reply received
- Conversation assigned
- Opportunity updated
- Meeting booked
- Opportunity won
Rules for the receiving address:
- HTTPS on port 443, with no query string. Redirects aren't followed.
- Your service must answer with a 2xx status within 10 seconds.
Each request is signed with HMAC-SHA256 in the Reachbook-Timestamp and Reachbook-Signature headers, so you can check it came from Reach-book.com. Failed deliveries are retried after 1 minute, 5 minutes, 30 minutes and 2 hours (5 attempts in total). The Activity tab shows every delivery.
Updated on: 04/10/2026
Thank you!