Sometimes somebody wants to connect something to Stippa. A website builder who wants to rebuild the booking form in your own house style, a bookkeeper with a script that pulls in revenue, or a service like Zapier that sends a message the moment an appointment comes in. Somebody like that will ask you for an API key.
This page is for you, not for that developer. You do not have to know how it works technically to make the right decision. What the developer needs is in the developer documentation, which is in English.
What is an API key?
A long, secret piece of text starting with stp_live_. Whoever holds it may do exactly the things
you ticked when you created it on behalf of your business, and nothing else.
Three things matter more than the technology:
- A key belongs to your business. It can never reach another business's data, not even by accident.
- A key is not a login. There is no password attached to it and nobody can walk into the app with it. It works only for the connection itself.
- A key is a secret, like a key to the shop. Whoever holds it can use it. That is exactly why the rest of this page exists.
When do I need one?
Only when somebody asks for one. For normal use of Stippa you never need an API key: the booking widget, the calendar, the emails and the public profile all work without one.
Typical cases where it does come up:
- Your website builder wants to work booking fully into your own site instead of using the standard widget.
- Somebody wants to put your appointments into a spreadsheet or accounting package automatically.
- You want a notification in Slack, Teams or Zapier as soon as somebody books.
Which subscription do I need?
| What you want | From |
|---|---|
| Reading data (appointments, customers, services, availability) | Groei |
| Having data created or changed, and webhooks | Pro |
If you move back to a lower subscription, the key simply goes on existing. The permissions your subscription no longer gives just stop working. Upgrade again later and the connection works straight away, with nobody having to configure anything.
Creating a key
You will find the keys in the Dev app, which sits in the app switcher at the top left as soon as you have switched the API access module on.
Switch the module on
Go to Management > Modules and switch API access on. The Dev app then appears in the app switcher.
Go to Dev > Keys
Click New key.
Give it a name you will still understand in a year
Not "test" or "key 2", but "Website Jansen Webdesign" or "Accounting connection". If you ever have to revoke something, the name is the only thing telling you which key belongs to whom.
Tick only what is needed
There are fixed combinations ready for you. If you are in doubt, pick Read only: that one can change nothing. Adding permissions later is not possible, but creating a second key is, and that is the safe order.
Copy the key straight away
You see the full key once, right after creating it. After that Stippa keeps only an encrypted form and even we cannot show it to you again. If you lose it, revoke it and create a new one.
Handing a key over safely
Sending the key once by email and then forgetting about it is how this usually goes wrong: a mailbox stays searchable for years, gets shared, and moves on to the next employer.
- Pass it on through a channel that deletes, or through the password vault the developer is using anyway.
- Never put it in a public message, a ticket or a shared document.
- Make a key of its own per party. Two companies on the same key means you break both connections when you have to revoke one.
- Ask for an end date if the job is temporary. You can let a key expire, and then nobody has to think about it later.
Revoking a key
Go to Dev > Keys and choose Revoke on the key in question. That takes effect immediately: the next request with that key is refused. Revoking cannot be undone, so the connection will need a new key afterwards.
Revoke in any case:
- when the arrangement with the builder or the agency ends;
- when the key has ended up somewhere it does not belong;
- when you no longer know what a key is for. A key nobody can place should not be active.
If you are unsure whether a key is still being used, look in Dev > Log first. There you can see per request when something came in and whether it worked. A key that has not appeared there for months can safely be revoked.
Webhooks: the other direction
A key lets somebody fetch data from you. A webhook does the opposite: Stippa sends a message to a web address as soon as something happens, when an appointment is booked or cancelled for instance. That is what a connection with Slack or Zapier needs. Webhooks are on the Pro subscription and live under Dev > Webhooks.
A webhook address deserves the same care as a key. On every event Stippa sends the matching data to that address, your customers' names, email addresses and phone numbers included. So whoever may set the address can make that stream run somewhere else. Only take an address from somebody you trust, and check the list if you no longer know who set up what.
If an address stays unreachable, Stippa retries a number of times and then switches the endpoint off automatically, so nothing is sent endlessly to a dead address. You see that as a notice above the list, with a button to switch it back on as soon as the receiver is working again.
Frequently asked questions
Can somebody log into Stippa with my key? No. A key works only for the connection and gives no access to the app, your account or your subscription.
Can a key reach another business's data? No. The key decides for itself which business it is about; there is no setting with which you could point at another one.
I cannot see the Dev app. The API access module is switched off, your subscription is Starter, or you are an employee. The app is visible to owners and admins.
My developer is asking for documentation. Send them to the developer documentation. It is in English and contains everything they need, examples included.