Last updated:
Ready to Try GoHighLevel?
Get the all-in-one platform for CRM, automations, funnels & websites — built for agencies.
Start your free trial and explore every feature.
The GoHighLevel API is HighLevel’s REST interface for reading and writing CRM data, such as contacts, opportunities, calendars and conversations, from your own code. You connect with a Private Integration Token for in-house tools or OAuth 2.0 for Marketplace apps, and the official documentation lives at marketplace.gohighlevel.com/docs. This guide covers authentication, plan access, key endpoints, webhooks, rate limits and security, based on HighLevel’s official pages as of October 2026.
What is the GoHighLevel API?
The HighLevel API (HighLevel also uses the LeadConnector brand) lets other software talk to a HighLevel agency or sub-account. HighLevel’s help center describes REST endpoints for contacts, messaging, workflows, calendars, payments and webhooks. Requests go to https://services.leadconnectorhq.com and send JSON.
Versions matter. HighLevel’s help center states that V1 APIs reached end of support on December 31, 2025, so new work should not use the old V1 API keys. The developer docs list several versions you choose with a Version request header: date-based versions such as 2021-07-28 and 2023-02-21, plus a named v3 version with a release date of June 11, 2026.
The help center still calls V2 the current generation and v3 the next milestone, so the two official sources use slightly different wording. In practice, pick a version in the docs version switcher, build against it, and send that same value in every request.
Where is the GoHighLevel API documentation?
The official GoHighLevel API documentation is the HighLevel developer site at marketplace.gohighlevel.com/docs. HighLevel’s own help article on the API points there as the official reference. The site includes:
- An endpoint reference grouped by area, such as Contacts, Calendars, Conversations and Opportunities
- Authorization guides for OAuth 2.0, Private Integration Tokens and scopes
- Webhook event pages and a webhook integration guide
- SDK pages for Node, PHP and Python, plus a Marketplace CLI
- Rate limit, versioning and changelog pages
Older versions keep their own docs paths, so check that the version shown at the top of the page matches the Version header your code sends. HighLevel support says it does not give hands-on coding or debugging help, so the docs and the developer community are your main resources.
New to GoHighLevel? Try it free for 30 days
Get HighLevel's official 30-day free trial and free Bootcamp through our partner link (the standard trial is 14 days). Prefer it done for you? We set up GoHighLevel from $499, with a free website.
Start 30-day free trialHave us set it upPartner link: we may earn a commission at no extra cost to you. Disclosure
How do you authenticate with the HighLevel API?
There are two supported methods. HighLevel’s help center frames the choice simply: Private Integration Tokens suit internal or single-account tools, while OAuth 2.0 suits public or Marketplace apps that need user-approved access across many accounts.
| Factor | Private Integration Token | OAuth 2.0 (Marketplace app) |
|---|---|---|
| Best for | Your own scripts, internal tools, one agency or sub-account | Apps installed on many accounts, public Marketplace apps |
| Where you create it | Settings > Private Integrations | Register an app in the HighLevel Marketplace developer portal |
| Token lifetime | Static until you rotate or delete it | Access token expires after about 24 hours; refresh token valid for 1 year or until used |
| Permissions | Scopes you select when you create it | Scopes the user approves at install |
| Header | Authorization: Bearer <token> | Authorization: Bearer <access_token> |
Private Integration Tokens
HighLevel’s docs describe Private Integrations as the way to build custom integrations between your account and a third-party app. They are available to both agencies and sub-accounts. You create one under Settings > Private Integrations, pick the scopes it needs, and copy the token once.
The docs recommend rotating these tokens every 90 days, and right away if one leaks. When you rotate, HighLevel can keep the old and new tokens working side by side for 7 days so you can swap them without downtime. If the menu item is missing, the docs say to check that the feature is turned on in Labs.
OAuth 2.0 for Marketplace apps
OAuth is the route for apps that many agencies or sub-accounts will install. You register an app, send users to its install URL, and exchange the returned code for tokens at https://services.leadconnectorhq.com/oauth/token. Access tokens last about 24 hours, so your app must use the refresh token to get new ones.
Tokens come in two levels: Company (agency) and Location (sub-account). An agency token can request a sub-account token through the /oauth/locationToken endpoint, which is useful for apps that manage many client accounts.
Which HighLevel plans include API access?
All three public plans include some API access as of October 2026. The HighLevel pricing page lists “Basic API Access” on Unlimited and “Advanced API Access” on Agency Pro. The help center adds that Starter and Unlimited get basic access, while Agency Pro unlocks advanced access.
| Plan (monthly price) | API access | What that means per HighLevel |
|---|---|---|
| Starter ($97/mo) | Basic | Location (sub-account) level access |
| Unlimited ($297/mo) | Basic | Location (sub-account) level access |
| Agency Pro ($497/mo) | Advanced | Adds agency-level tokens and OAuth 2.0 API features |
HighLevel also notes that some endpoints may only be available on higher plans. If your project needs agency-wide automation, such as creating sub-accounts, confirm the endpoint and plan before you start. Our GoHighLevel pricing breakdown covers the plans in more detail.
What can you build with the GoHighLevel API?
Most real projects use a small set of endpoints. Here are four we see most often, with paths taken from the official docs as of October 2026.
| Area | Endpoint | Typical use |
|---|---|---|
| Contacts | POST /contacts/upsert | Create or update a lead from a website, app or other CRM |
| Opportunities | GET /opportunities/search | Pull deals by pipeline, stage or status for reports |
| Calendars | GET /calendars/:calendarId/free-slots | Show open booking times in a custom app or chatbot |
| Conversations | POST /conversations/messages | Send an SMS, email or other message to a contact |
Common use cases include:
- Syncing leads from a custom website, booking engine or ERP into HighLevel
- Building a client dashboard that pulls pipeline numbers into your own reporting tool
- Letting a chatbot or voice agent check calendar slots before offering times
- Sending order or delivery updates from an e-commerce system as texts
- Pushing won deals into accounting or project tools
Example: create or update a contact
The upsert endpoint follows the sub-account’s duplicate contact setting, matching on email or phone to decide whether to create or update. Replace every value in angle brackets with your own; never paste a real token into shared docs.
curl -X POST "https://services.leadconnectorhq.com/contacts/upsert" \
-H "Authorization: Bearer <YOUR_PRIVATE_INTEGRATION_TOKEN>" \
-H "Version: <API_VERSION_FROM_DOCS>" \
-H "Content-Type: application/json" \
-d '{
"locationId": "<YOUR_LOCATION_ID>",
"firstName": "Jane",
"lastName": "Example",
"email": "jane@example.com",
"phone": "+15555550123"
}'Example: check open calendar slots
The free-slots endpoint takes a start and end date as numbers and cannot cover more than 31 days at once. A simple flow in pseudo-code looks like this:
// Pseudo-code: placeholders in angle brackets
GET https://services.leadconnectorhq.com/calendars/<CALENDAR_ID>/free-slots
?startDate=<START_MS>&endDate=<END_MS>&timezone=America/New_York
Headers: Authorization: Bearer <TOKEN>, Version: <API_VERSION_FROM_DOCS>
for each date in response:
show date.slots to the visitorHow do GoHighLevel webhooks work?
Webhooks push data to you when something happens, so you do not have to poll the API. HighLevel offers two kinds, and they suit different jobs.
Marketplace app webhooks
An OAuth app can subscribe to webhook events, which the docs describe as more than 50 event types, such as ContactCreate, ContactUpdate and AppointmentCreate. Each event arrives as a JSON POST to the URL you set in the app.
Verify every request. The webhook guide says HighLevel signs payloads with an X-GHL-Signature header (Ed25519), and that the older X-WH-Signature header (RSA) was set for deprecation on September 1, 2026. Check the signature with HighLevel’s published public key and reject anything that fails.
Workflow webhooks
Inside any workflow, the Inbound Webhook trigger starts a workflow when an outside system sends data to a HighLevel URL. The Custom Webhook action does the reverse, calling any URL with GET, POST, PUT or DELETE and options such as bearer token, API key, basic auth or OAuth2.
Both are premium workflow features. HighLevel’s help center lists premium executions at $0.01 each after 100 free lifetime executions per sub-account, as of October 2026. Our guide to GHL workflows for lead follow-up shows where these fit in a typical build.
What are the GoHighLevel API rate limits?
As of October 2026, HighLevel lists two limits for its public V2 APIs using OAuth:
- Burst: 100 requests per 10 seconds
- Daily: 200,000 requests per day
Both are counted per Marketplace app per resource, where a resource is one sub-account (Location) or agency (Company). Each response carries headers such as X-RateLimit-Remaining and X-RateLimit-Daily-Remaining, so your code can slow down before it hits the cap.
For bulk jobs like migrations, queue requests and back off when the remaining count runs low. HighLevel’s Enterprise plan lists higher API limits by request if you outgrow these numbers.
What are the security best practices for the HighLevel API?
An API token can read and change client data, so treat it like a password. These habits cover most risks:
- Grant the fewest scopes the integration needs, and create one token per integration
- Store tokens in a secrets manager or environment variables, never in front-end code or Git
- Rotate Private Integration Tokens at least every 90 days, as HighLevel recommends
- Verify the
X-GHL-Signatureheader on every incoming webhook - Refresh OAuth tokens on the server side and store refresh tokens encrypted
- Log API errors, but strip phone numbers, emails and tokens from the logs
- Keep a test sub-account for development so bad code never touches live client data
If you handle health data, also read our notes on GoHighLevel HIPAA compliance before you pass that data through any integration.
Should you use the API, Zapier, webhooks or MCP?
The API is the most flexible option, but it is also the most work to build and maintain. Many tasks are simpler with another tool.
| Option | Best when | Trade-off |
|---|---|---|
| Zapier (LeadConnector app) | You need a simple link to a popular app with no code | Limited triggers and per-task costs |
| Workflow webhooks | A HighLevel event should call one outside URL, or an outside tool should start a workflow | Premium execution charges; little logic outside the workflow |
| Direct API | You need full control, bulk data, custom apps or two-way sync | Needs a developer, hosting and upkeep |
| MCP server | You want an AI assistant such as Claude to read and update the CRM in plain language | Suits hands-on, assisted work more than silent background syncs |
HighLevel’s docs describe an official LeadConnector MCP server that connects AI assistants through OAuth and exposes more than 550 operations across 38 areas. Our Claude and GHL MCP setup guide walks through the connection. Our founder also built GHL MCP (ghlmcp.io), a tool for connecting AI assistants to GoHighLevel.
For a no-code view of the Zapier route, see our GoHighLevel Zapier integration guide.
Need a custom GoHighLevel integration built?
AutoGen CRM has built HighLevel systems for 4+ years across 120+ projects, including API syncs, webhook flows and AI connections. Our GoHighLevel workflow service includes the Custom Workflow Pack at $350 per 5 built and tested workflows, and larger API projects get a fixed quote after a free call.
See every package on our pricing page, book a free call, or phone +1 (681) 276-7045, Monday to Friday, 9:00 AM to 5:00 PM ET.
Frequently Asked Questions
Is the GoHighLevel API free?
There is no separate API fee on HighLevel’s public plans as of October 2026. Starter and Unlimited include basic API access, and Agency Pro includes advanced access with agency-level tokens and OAuth features. Messages you send through the API, such as SMS and email, still use HighLevel’s normal usage pricing, and premium workflow webhooks carry per-execution charges.
Where do I find my GoHighLevel API key?
HighLevel is removing the option to generate new legacy API keys, and V1 APIs reached end of support on December 31, 2025. Create a Private Integration Token instead under Settings > Private Integrations, choose its scopes and copy the token. If you do not see the menu, HighLevel’s docs say to check that the feature is enabled in Labs.
What is the difference between the HighLevel API and LeadConnector?
They are the same platform. LeadConnector is HighLevel’s white-label brand, which is why the API base URL uses services.leadconnectorhq.com and the Zapier app is called LeadConnector. Any token or endpoint from the HighLevel docs works with that LeadConnector domain, and the data lives in the same HighLevel account.
Can I use the GoHighLevel API on the Starter plan?
Yes. HighLevel’s help center says basic API access is included with Starter and Unlimited as of October 2026. Basic access works at the sub-account (Location) level. If you need agency-level tokens, for example to create or manage many sub-accounts from code, HighLevel ties that to Advanced API access on Agency Pro.
Does HighLevel support help with API code?
No. HighLevel’s help center says its support team does not provide hands-on API development or debugging. Developers are pointed to the official docs, the developer community and a developer support portal. If you do not have a developer in house, an agency that builds HighLevel integrations can scope, build and test the work for you.
How many API calls can I make per day?
HighLevel lists 200,000 requests per day and a burst limit of 100 requests per 10 seconds as of October 2026. These limits are counted per Marketplace app for each sub-account or agency, so each installation has its own budget. Watch the rate limit headers in each response and back off as you approach the cap.
Ready to Get Your GoHighLevel System Built?
We'll build your entire GHL setup for $499 and give you a free professional website.
Book a Free Call See Packages & PricingOr call +1 (681) 276-7045 · Mon–Fri, 9 AM–5 PM ET


