GoHighLevel API: A Practical Guide for 2026

GoHighLevel API: A Practical Guide for 2026 – AutoGen CRM

Last updated:

The GoHighLevel API is HighLevel’s REST interface for reading and writing CRM data, such as contacts, opportunities, calendars and conversations, from your own code. You connect with a Private Integration Token for in-house tools or OAuth 2.0 for Marketplace apps, and the official documentation lives at marketplace.gohighlevel.com/docs. This guide covers authentication, plan access, key endpoints, webhooks, rate limits and security, based on HighLevel’s official pages as of October 2026.

What is the GoHighLevel API?

The HighLevel API (HighLevel also uses the LeadConnector brand) lets other software talk to a HighLevel agency or sub-account. HighLevel’s help center describes REST endpoints for contacts, messaging, workflows, calendars, payments and webhooks. Requests go to https://services.leadconnectorhq.com and send JSON.

Versions matter. HighLevel’s help center states that V1 APIs reached end of support on December 31, 2025, so new work should not use the old V1 API keys. The developer docs list several versions you choose with a Version request header: date-based versions such as 2021-07-28 and 2023-02-21, plus a named v3 version with a release date of June 11, 2026.

The help center still calls V2 the current generation and v3 the next milestone, so the two official sources use slightly different wording. In practice, pick a version in the docs version switcher, build against it, and send that same value in every request.

Where is the GoHighLevel API documentation?

The official GoHighLevel API documentation is the HighLevel developer site at marketplace.gohighlevel.com/docs. HighLevel’s own help article on the API points there as the official reference. The site includes:

  • An endpoint reference grouped by area, such as Contacts, Calendars, Conversations and Opportunities
  • Authorization guides for OAuth 2.0, Private Integration Tokens and scopes
  • Webhook event pages and a webhook integration guide
  • SDK pages for Node, PHP and Python, plus a Marketplace CLI
  • Rate limit, versioning and changelog pages

Older versions keep their own docs paths, so check that the version shown at the top of the page matches the Version header your code sends. HighLevel support says it does not give hands-on coding or debugging help, so the docs and the developer community are your main resources.

New to GoHighLevel? Try it free for 30 days

Get HighLevel's official 30-day free trial and free Bootcamp through our partner link (the standard trial is 14 days). Prefer it done for you? We set up GoHighLevel from $499, with a free website.

Start 30-day free trialHave us set it up

Partner link: we may earn a commission at no extra cost to you. Disclosure

How do you authenticate with the HighLevel API?

There are two supported methods. HighLevel’s help center frames the choice simply: Private Integration Tokens suit internal or single-account tools, while OAuth 2.0 suits public or Marketplace apps that need user-approved access across many accounts.

FactorPrivate Integration TokenOAuth 2.0 (Marketplace app)
Best forYour own scripts, internal tools, one agency or sub-accountApps installed on many accounts, public Marketplace apps
Where you create itSettings > Private IntegrationsRegister an app in the HighLevel Marketplace developer portal
Token lifetimeStatic until you rotate or delete itAccess token expires after about 24 hours; refresh token valid for 1 year or until used
PermissionsScopes you select when you create itScopes the user approves at install
HeaderAuthorization: Bearer <token>Authorization: Bearer <access_token>

Private Integration Tokens

HighLevel’s docs describe Private Integrations as the way to build custom integrations between your account and a third-party app. They are available to both agencies and sub-accounts. You create one under Settings > Private Integrations, pick the scopes it needs, and copy the token once.

The docs recommend rotating these tokens every 90 days, and right away if one leaks. When you rotate, HighLevel can keep the old and new tokens working side by side for 7 days so you can swap them without downtime. If the menu item is missing, the docs say to check that the feature is turned on in Labs.

OAuth 2.0 for Marketplace apps

OAuth is the route for apps that many agencies or sub-accounts will install. You register an app, send users to its install URL, and exchange the returned code for tokens at https://services.leadconnectorhq.com/oauth/token. Access tokens last about 24 hours, so your app must use the refresh token to get new ones.

Tokens come in two levels: Company (agency) and Location (sub-account). An agency token can request a sub-account token through the /oauth/locationToken endpoint, which is useful for apps that manage many client accounts.

Which HighLevel plans include API access?

All three public plans include some API access as of October 2026. The HighLevel pricing page lists “Basic API Access” on Unlimited and “Advanced API Access” on Agency Pro. The help center adds that Starter and Unlimited get basic access, while Agency Pro unlocks advanced access.

Plan (monthly price)API accessWhat that means per HighLevel
Starter ($97/mo)BasicLocation (sub-account) level access
Unlimited ($297/mo)BasicLocation (sub-account) level access
Agency Pro ($497/mo)AdvancedAdds agency-level tokens and OAuth 2.0 API features

HighLevel also notes that some endpoints may only be available on higher plans. If your project needs agency-wide automation, such as creating sub-accounts, confirm the endpoint and plan before you start. Our GoHighLevel pricing breakdown covers the plans in more detail.

What can you build with the GoHighLevel API?

Most real projects use a small set of endpoints. Here are four we see most often, with paths taken from the official docs as of October 2026.

AreaEndpointTypical use
ContactsPOST /contacts/upsertCreate or update a lead from a website, app or other CRM
OpportunitiesGET /opportunities/searchPull deals by pipeline, stage or status for reports
CalendarsGET /calendars/:calendarId/free-slotsShow open booking times in a custom app or chatbot
ConversationsPOST /conversations/messagesSend an SMS, email or other message to a contact

Common use cases include:

  • Syncing leads from a custom website, booking engine or ERP into HighLevel
  • Building a client dashboard that pulls pipeline numbers into your own reporting tool
  • Letting a chatbot or voice agent check calendar slots before offering times
  • Sending order or delivery updates from an e-commerce system as texts
  • Pushing won deals into accounting or project tools

Example: create or update a contact

The upsert endpoint follows the sub-account’s duplicate contact setting, matching on email or phone to decide whether to create or update. Replace every value in angle brackets with your own; never paste a real token into shared docs.

curl -X POST "https://services.leadconnectorhq.com/contacts/upsert" \
  -H "Authorization: Bearer <YOUR_PRIVATE_INTEGRATION_TOKEN>" \
  -H "Version: <API_VERSION_FROM_DOCS>" \
  -H "Content-Type: application/json" \
  -d '{
    "locationId": "<YOUR_LOCATION_ID>",
    "firstName": "Jane",
    "lastName": "Example",
    "email": "jane@example.com",
    "phone": "+15555550123"
  }'

Example: check open calendar slots

The free-slots endpoint takes a start and end date as numbers and cannot cover more than 31 days at once. A simple flow in pseudo-code looks like this:

// Pseudo-code: placeholders in angle brackets
GET https://services.leadconnectorhq.com/calendars/<CALENDAR_ID>/free-slots
    ?startDate=<START_MS>&endDate=<END_MS>&timezone=America/New_York
Headers: Authorization: Bearer <TOKEN>, Version: <API_VERSION_FROM_DOCS>

for each date in response:
    show date.slots to the visitor

How do GoHighLevel webhooks work?

Webhooks push data to you when something happens, so you do not have to poll the API. HighLevel offers two kinds, and they suit different jobs.

Marketplace app webhooks

An OAuth app can subscribe to webhook events, which the docs describe as more than 50 event types, such as ContactCreate, ContactUpdate and AppointmentCreate. Each event arrives as a JSON POST to the URL you set in the app.

Verify every request. The webhook guide says HighLevel signs payloads with an X-GHL-Signature header (Ed25519), and that the older X-WH-Signature header (RSA) was set for deprecation on September 1, 2026. Check the signature with HighLevel’s published public key and reject anything that fails.

Workflow webhooks

Inside any workflow, the Inbound Webhook trigger starts a workflow when an outside system sends data to a HighLevel URL. The Custom Webhook action does the reverse, calling any URL with GET, POST, PUT or DELETE and options such as bearer token, API key, basic auth or OAuth2.

Both are premium workflow features. HighLevel’s help center lists premium executions at $0.01 each after 100 free lifetime executions per sub-account, as of October 2026. Our guide to GHL workflows for lead follow-up shows where these fit in a typical build.

What are the GoHighLevel API rate limits?

As of October 2026, HighLevel lists two limits for its public V2 APIs using OAuth:

  • Burst: 100 requests per 10 seconds
  • Daily: 200,000 requests per day

Both are counted per Marketplace app per resource, where a resource is one sub-account (Location) or agency (Company). Each response carries headers such as X-RateLimit-Remaining and X-RateLimit-Daily-Remaining, so your code can slow down before it hits the cap.

For bulk jobs like migrations, queue requests and back off when the remaining count runs low. HighLevel’s Enterprise plan lists higher API limits by request if you outgrow these numbers.

What are the security best practices for the HighLevel API?

An API token can read and change client data, so treat it like a password. These habits cover most risks:

  • Grant the fewest scopes the integration needs, and create one token per integration
  • Store tokens in a secrets manager or environment variables, never in front-end code or Git
  • Rotate Private Integration Tokens at least every 90 days, as HighLevel recommends
  • Verify the X-GHL-Signature header on every incoming webhook
  • Refresh OAuth tokens on the server side and store refresh tokens encrypted
  • Log API errors, but strip phone numbers, emails and tokens from the logs
  • Keep a test sub-account for development so bad code never touches live client data

If you handle health data, also read our notes on GoHighLevel HIPAA compliance before you pass that data through any integration.

Should you use the API, Zapier, webhooks or MCP?

The API is the most flexible option, but it is also the most work to build and maintain. Many tasks are simpler with another tool.

OptionBest whenTrade-off
Zapier (LeadConnector app)You need a simple link to a popular app with no codeLimited triggers and per-task costs
Workflow webhooksA HighLevel event should call one outside URL, or an outside tool should start a workflowPremium execution charges; little logic outside the workflow
Direct APIYou need full control, bulk data, custom apps or two-way syncNeeds a developer, hosting and upkeep
MCP serverYou want an AI assistant such as Claude to read and update the CRM in plain languageSuits hands-on, assisted work more than silent background syncs

HighLevel’s docs describe an official LeadConnector MCP server that connects AI assistants through OAuth and exposes more than 550 operations across 38 areas. Our Claude and GHL MCP setup guide walks through the connection. Our founder also built GHL MCP (ghlmcp.io), a tool for connecting AI assistants to GoHighLevel.

For a no-code view of the Zapier route, see our GoHighLevel Zapier integration guide.

Need a custom GoHighLevel integration built?

AutoGen CRM has built HighLevel systems for 4+ years across 120+ projects, including API syncs, webhook flows and AI connections. Our GoHighLevel workflow service includes the Custom Workflow Pack at $350 per 5 built and tested workflows, and larger API projects get a fixed quote after a free call.

See every package on our pricing page, book a free call, or phone +1 (681) 276-7045, Monday to Friday, 9:00 AM to 5:00 PM ET.

Frequently Asked Questions

Is the GoHighLevel API free?

There is no separate API fee on HighLevel’s public plans as of October 2026. Starter and Unlimited include basic API access, and Agency Pro includes advanced access with agency-level tokens and OAuth features. Messages you send through the API, such as SMS and email, still use HighLevel’s normal usage pricing, and premium workflow webhooks carry per-execution charges.

Where do I find my GoHighLevel API key?

HighLevel is removing the option to generate new legacy API keys, and V1 APIs reached end of support on December 31, 2025. Create a Private Integration Token instead under Settings > Private Integrations, choose its scopes and copy the token. If you do not see the menu, HighLevel’s docs say to check that the feature is enabled in Labs.

What is the difference between the HighLevel API and LeadConnector?

They are the same platform. LeadConnector is HighLevel’s white-label brand, which is why the API base URL uses services.leadconnectorhq.com and the Zapier app is called LeadConnector. Any token or endpoint from the HighLevel docs works with that LeadConnector domain, and the data lives in the same HighLevel account.

Can I use the GoHighLevel API on the Starter plan?

Yes. HighLevel’s help center says basic API access is included with Starter and Unlimited as of October 2026. Basic access works at the sub-account (Location) level. If you need agency-level tokens, for example to create or manage many sub-accounts from code, HighLevel ties that to Advanced API access on Agency Pro.

Does HighLevel support help with API code?

No. HighLevel’s help center says its support team does not provide hands-on API development or debugging. Developers are pointed to the official docs, the developer community and a developer support portal. If you do not have a developer in house, an agency that builds HighLevel integrations can scope, build and test the work for you.

How many API calls can I make per day?

HighLevel lists 200,000 requests per day and a burst limit of 100 requests per 10 seconds as of October 2026. These limits are counted per Marketplace app for each sub-account or agency, so each installation has its own budget. Watch the rate limit headers in each response and back off as you approach the cap.

Ready to Get Your GoHighLevel System Built?

We'll build your entire GHL setup for $499 and give you a free professional website.

Book a Free Call See Packages & Pricing

Or call +1 (681) 276-7045 · Mon–Fri, 9 AM–5 PM ET

Leave a Comment

Your email address will not be published. Required fields are marked *

Scroll to Top