API keys

API keys

Create, scope and revoke keys for the Heizen API.

Open Developers → API keys and choose Create API key.

  1. Name the key after the system that will use it, such as "ATS sync".
  2. Pick the mode. Test keys (hz_test_…) never use credits. Live keys (hz_live_…) work on real data.
  3. Tick the scopes the integration needs and nothing more.
  4. Copy the key. This is the only time Heizen shows it in full; afterwards the list shows only the last four characters.

You can only grant scopes your own role holds.

Scopes

ScopeAllows
interviewers:readList and read interviewers
candidates:readList and read candidates and invitations
candidates:writeCreate, update and delete candidates
candidates:importImport spreadsheets and read imports
invitations:sendCreate, bulk-create, resend, extend and cancel invitations
results:readRead sessions, transcripts, recordings, events and results
results:exportCreate and download exports
developers:manageManage webhook endpoints and read events
billing:readRead credit usage

GET /v1/ping and GET /v1/me work with any valid key.

Revoking and rotating

Revoke stops a key at once; requests with it get 401 invalid_api_key. To rotate without downtime, create the new key, deploy it, check Last used on the old key has stopped moving, then revoke the old one.

If a key leaks, revoke it first and investigate after.