Skip to main content
1

Create a key

An organization administrator opens Settings → Integrations → API keys → New key.
  • For a website or landing-page form, choose Website form. That key can only capture leads.
  • For any other application, choose the scopes it needs. See Keys and scopes.
Copy the key as soon as it is shown. Marro cannot show it again.
2

Keep it on your server

Store the key as an environment variable on your server, for example MARRO_API_KEY. Never put it in browser JavaScript, a mobile app or a URL.
3

Make a request

Send the key in the Authorization header as a bearer token: Authorization: Bearer <key>.An organization API key, created in Settings → Integrations → API keys. Keys start with mk_live_. Marro stores only a hash of a key, so it is shown once, when it is created: copy it then. Revoking a key ends its access at once. To replace a key without downtime, create the new one, switch your server to it, then revoke the old one. Changes made with a key appear on the lead’s timeline as made by the person who created the key, via the API. Scopes: leads.read (Read leads), leads.write (Create and update leads), leads.capture (Capture leads).
Requests are refused before the key is checked when:
Next: Connect a website or browse the API reference.