Skip to content
Stippa
FeaturesPricingDemoHelpContact
Log inStart free
Settings

API keys and webhooks

What an API key is, when you need one, how to hand one to your developer safely and how to revoke it again.

6 min read

Sometimes somebody wants to connect something to Stippa. A website builder who wants to rebuild the booking form in your own house style, a bookkeeper with a script that pulls in revenue, or a service like Zapier that sends a message the moment an appointment comes in. Somebody like that will ask you for an API key.

This page is for you, not for that developer. You do not have to know how it works technically to make the right decision. What the developer needs is in the developer documentation, which is in English.

What is an API key?

A long, secret piece of text starting with stp_live_. Whoever holds it may do exactly the things you ticked when you created it on behalf of your business, and nothing else.

Three things matter more than the technology:

  • A key belongs to your business. It can never reach another business's data, not even by accident.
  • A key is not a login. There is no password attached to it and nobody can walk into the app with it. It works only for the connection itself.
  • A key is a secret, like a key to the shop. Whoever holds it can use it. That is exactly why the rest of this page exists.

When do I need one?

Only when somebody asks for one. For normal use of Stippa you never need an API key: the booking widget, the calendar, the emails and the public profile all work without one.

Typical cases where it does come up:

  • Your website builder wants to work booking fully into your own site instead of using the standard widget.
  • Somebody wants to put your appointments into a spreadsheet or accounting package automatically.
  • You want a notification in Slack, Teams or Zapier as soon as somebody books.

Which subscription do I need?

What you wantFrom
Reading data (appointments, customers, services, availability)Groei
Having data created or changed, and webhooksPro

If you move back to a lower subscription, the key simply goes on existing. The permissions your subscription no longer gives just stop working. Upgrade again later and the connection works straight away, with nobody having to configure anything.

Creating a key

You will find the keys in the Dev app, which sits in the app switcher at the top left as soon as you have switched the API access module on.

1

Switch the module on

Go to Management > Modules and switch API access on. The Dev app then appears in the app switcher.

2

Go to Dev > Keys

Click New key.

3

Give it a name you will still understand in a year

Not "test" or "key 2", but "Website Jansen Webdesign" or "Accounting connection". If you ever have to revoke something, the name is the only thing telling you which key belongs to whom.

4

Tick only what is needed

There are fixed combinations ready for you. If you are in doubt, pick Read only: that one can change nothing. Adding permissions later is not possible, but creating a second key is, and that is the safe order.

5

Copy the key straight away

You see the full key once, right after creating it. After that Stippa keeps only an encrypted form and even we cannot show it to you again. If you lose it, revoke it and create a new one.

Handing a key over safely

Sending the key once by email and then forgetting about it is how this usually goes wrong: a mailbox stays searchable for years, gets shared, and moves on to the next employer.

  • Pass it on through a channel that deletes, or through the password vault the developer is using anyway.
  • Never put it in a public message, a ticket or a shared document.
  • Make a key of its own per party. Two companies on the same key means you break both connections when you have to revoke one.
  • Ask for an end date if the job is temporary. You can let a key expire, and then nobody has to think about it later.

Revoking a key

Go to Dev > Keys and choose Revoke on the key in question. That takes effect immediately: the next request with that key is refused. Revoking cannot be undone, so the connection will need a new key afterwards.

Revoke in any case:

  • when the arrangement with the builder or the agency ends;
  • when the key has ended up somewhere it does not belong;
  • when you no longer know what a key is for. A key nobody can place should not be active.

If you are unsure whether a key is still being used, look in Dev > Log first. There you can see per request when something came in and whether it worked. A key that has not appeared there for months can safely be revoked.

Webhooks: the other direction

A key lets somebody fetch data from you. A webhook does the opposite: Stippa sends a message to a web address as soon as something happens, when an appointment is booked or cancelled for instance. That is what a connection with Slack or Zapier needs. Webhooks are on the Pro subscription and live under Dev > Webhooks.

⚠️

A webhook address deserves the same care as a key. On every event Stippa sends the matching data to that address, your customers' names, email addresses and phone numbers included. So whoever may set the address can make that stream run somewhere else. Only take an address from somebody you trust, and check the list if you no longer know who set up what.

If an address stays unreachable, Stippa retries a number of times and then switches the endpoint off automatically, so nothing is sent endlessly to a dead address. You see that as a notice above the list, with a button to switch it back on as soon as the receiver is working again.

Frequently asked questions

Can somebody log into Stippa with my key? No. A key works only for the connection and gives no access to the app, your account or your subscription.

Can a key reach another business's data? No. The key decides for itself which business it is about; there is no setting with which you could point at another one.

I cannot see the Dev app. The API access module is switched off, your subscription is Starter, or you are an employee. The app is visible to owners and admins.

My developer is asking for documentation. Send them to the developer documentation. It is in English and contains everything they need, examples included.

Updated: 1 August 2026

Was dit artikel nuttig?

Related articles

  • Restyling your booking widget
  • Plans, limits and what each one includes

In this article

  • What is an API key?
  • When do I need one?
  • Which subscription do I need?
  • Creating a key
  • Handing a key over safely
  • Revoking a key
  • Webhooks: the other direction
  • Frequently asked questions
Stippa

Appointment scheduling, without the hassle.

Start 14 days free

Product

  • Features
  • Pricing
  • Demo
  • FAQ
  • Contact
  • System status

Features

  • Booking widget
  • Online payments
  • Reminders
  • No-show prevention
  • Online calendar
  • Your own website
  • Client management

For whom

  • For salons
  • Beauty salons
  • Physiotherapists
  • Coaches
  • Personal trainers
  • Barbershops
  • Nail salons
  • Pedicurists
  • Massage salons

Legal

  • Privacy policy
  • Terms of service
  • Data processing agreement

© 2026 Stippa. All rights reserved.

De Rechter Software · Molenwater 20, 4511 BN Breskens · KvK 98466402 · btw NL005332100B80

······
Start 14 days free

14 days free. No card needed.