Developers

Issue and use API keys

API access is on every plan. Issue a named key, tick only the scopes you need, copy the secret once, and send it as a bearer credential.

1 of 5 in Developers

Plan: API keys on every plan. Rate limits apply per plan.
API and webhooks area of PayBlah settings
Showcase book · Harbour Print & Signage (sample data) · light theme

Open Settings → API & Webhooks (Admin required to issue or revoke).

Issue a key

  1. Name the key (for example "Zapier" or "Warehouse sync").
  2. Tick scopes only for what the integration needs. Examples from the product: read/write debtors, read/write invoices, read/record payments, read the message log. Read and write are separate on purpose.
  3. Press Issue key.
  4. Copy the secret immediately. PayBlah stores only a hash — this is the only time the full key is shown.

Use the key

Call the public REST API with the key as a bearer credential. Prefer server-side storage; never embed secrets in a debtor-facing page.

Revoke

Press Revoke on a row. Revocation is immediate — the next call returns 401 Unauthorized. Only the prefix remains visible in the list.

What Standard users see

They can view the inventory. Only an Admin can issue or revoke. If a key looks wrong, ask an Admin to revoke it.

PayBlah is accounts-receivable automation software. You remain the creditor. Confirm local rules with your own advisor for your territory (US, UK, Ireland, or Australia).