curl --request GET \
--url https://{subdomain}.conveyour.com/api/hooks/credentials \
--header 'x-conveyour-token: <api-key>'const options = {method: 'GET', headers: {'x-conveyour-token': '<api-key>'}};
fetch('https://{subdomain}.conveyour.com/api/hooks/credentials', options)
.then(res => res.json())
.then(res => console.log(res))
.catch(err => console.error(err));const options = {method: 'GET', headers: {'x-conveyour-token': '<api-key>'}};
fetch('https://{subdomain}.conveyour.com/api/hooks/credentials', options)
.then(res => res.json())
.then(res => console.log(res))
.catch(err => console.error(err));import requests
url = "https://{subdomain}.conveyour.com/api/hooks/credentials"
headers = {"x-conveyour-token": "<api-key>"}
response = requests.get(url, headers=headers)
print(response.text)<?php
$curl = curl_init();
curl_setopt_array($curl, [
CURLOPT_URL => "https://{subdomain}.conveyour.com/api/hooks/credentials",
CURLOPT_RETURNTRANSFER => true,
CURLOPT_ENCODING => "",
CURLOPT_MAXREDIRS => 10,
CURLOPT_TIMEOUT => 30,
CURLOPT_HTTP_VERSION => CURL_HTTP_VERSION_1_1,
CURLOPT_CUSTOMREQUEST => "GET",
CURLOPT_HTTPHEADER => [
"x-conveyour-token: <api-key>"
],
]);
$response = curl_exec($curl);
$err = curl_error($curl);
curl_close($curl);
if ($err) {
echo "cURL Error #:" . $err;
} else {
echo $response;
}{
"status": "ok",
"message": "success",
"data": {
"appkey": "hook",
"token": "64a1b2c3d4e5f6a7b8c9d0e1"
}
}{
"status": "failed",
"message": "Lacking necessary permission add_contacts",
"data": {
"permission": "add_contacts"
}
}Get hook credentials
Returns the legacy hook credential pair (appkey and token) for the authenticated user, if one exists. Auto-minting of hook credentials has been removed. This endpoint only returns an existing credential — it will not create one. Create API keys in Settings → API instead.
Get the existing legacy hook credential pair
Permission: requires hooks.
Not callable with an API key. Requires hooks, which ConveYour never grants to service accounts (deny_for_types: [service]), so every API key gets 403. Only a signed-in user with this permission can call it.
curl --request GET \
--url https://{subdomain}.conveyour.com/api/hooks/credentials \
--header 'x-conveyour-token: <api-key>'const options = {method: 'GET', headers: {'x-conveyour-token': '<api-key>'}};
fetch('https://{subdomain}.conveyour.com/api/hooks/credentials', options)
.then(res => res.json())
.then(res => console.log(res))
.catch(err => console.error(err));const options = {method: 'GET', headers: {'x-conveyour-token': '<api-key>'}};
fetch('https://{subdomain}.conveyour.com/api/hooks/credentials', options)
.then(res => res.json())
.then(res => console.log(res))
.catch(err => console.error(err));import requests
url = "https://{subdomain}.conveyour.com/api/hooks/credentials"
headers = {"x-conveyour-token": "<api-key>"}
response = requests.get(url, headers=headers)
print(response.text)<?php
$curl = curl_init();
curl_setopt_array($curl, [
CURLOPT_URL => "https://{subdomain}.conveyour.com/api/hooks/credentials",
CURLOPT_RETURNTRANSFER => true,
CURLOPT_ENCODING => "",
CURLOPT_MAXREDIRS => 10,
CURLOPT_TIMEOUT => 30,
CURLOPT_HTTP_VERSION => CURL_HTTP_VERSION_1_1,
CURLOPT_CUSTOMREQUEST => "GET",
CURLOPT_HTTPHEADER => [
"x-conveyour-token: <api-key>"
],
]);
$response = curl_exec($curl);
$err = curl_error($curl);
curl_close($curl);
if ($err) {
echo "cURL Error #:" . $err;
} else {
echo $response;
}{
"status": "ok",
"message": "success",
"data": {
"appkey": "hook",
"token": "64a1b2c3d4e5f6a7b8c9d0e1"
}
}{
"status": "failed",
"message": "Lacking necessary permission add_contacts",
"data": {
"permission": "add_contacts"
}
}Authorizations
Your API key token. Contacts endpoints require a Server-only — Full API key — see Authentication.
Query Parameters
Team scope for the request, as one or more team ObjectIds. The brackets are required: PHP keeps only the last value for a repeated plain key, so teams=A&teams=B silently resolves to B alone. On requests with a JSON body you may send teams (no brackets) in the body instead.
Values that are not valid ObjectIds are silently ignored — a mistyped team ID behaves as if no team was sent. See the teams section of the API conventions guide.
Response
Success.
The common response envelope shared by all ConveYour endpoints.