Connect your tools to your repair shop

On Business, choose which types of records each API key can read or change. Signed webhooks notify your server when a ticket changes status or an invoice is paid.

The owner creates a Live key for the bench tablet with Customers Read and Tickets Read and Write, then copies the key.

Review access and connect your server

  1. 1

    Check each key's access

    A key's details show its permissions and last use, alongside request counts, error rate and average response time over the last 30 days.

  2. 2

    Choose events to send

    In Webhooks, select the events your tool needs, such as ticket status changes or paid invoices. Notifications go to your server's public HTTPS address.

  3. 3

    Verify each delivery's signature

    The signing secret appears once when you create a webhook. Your developer uses it to verify the BenchKey-Signature header on incoming deliveries.

Keep deliveries signed while changing secrets

A new signing secret leaves the previous one valid for 24 hours. During that window, deliveries carry signatures for both while your developer updates the receiving server.

Control access as your shop's tools change

Manage key permissions and replacements, with documented limits and retry behavior for the tools your developer builds.

Keep access during key changes

A replacement keeps the same environment label and scopes. Keep the old key working for up to 24 hours while you update the connected tool.

Revoke a key immediately

Revoking a key stops its access immediately. The key stays in the list below active keys, so you can still see it was revoked.

Choose read access in bulk

The Read-only button selects all read scopes without write access. Remove any your tool does not need to limit which record types it can view.

Request limits for each key
Each key allows bursts of 100 requests, refilling at 10 per second. Response headers show remaining capacity and the wait before retrying.
Reuse completed write results
An Idempotency-Key lets identical retries reuse a completed response for 24 hours without repeating the write. Check uncertain outcomes before sending another request.
Give developers the full reference
The API docs link opens the reference for authentication, errors and resource endpoints. The OpenAPI specification also describes supported operations.

Plans, testing and delivery behavior

API keys and public API access are included on Business. Standard and Pro do not include API access.

Compare plans
Which plan includes API access?

Business includes API access. Standard and Pro require an upgrade to create keys. The public API must also be enabled for your environment. The API reference covers authentication, supported endpoints and errors.

Does a Test key create a sandbox?

No. Test and Live keys read and change the same workspace's real data within their scopes. Use a separate workspace with fictional data for development, and read-only access when your tool only needs to view records.

How can we verify a webhook came from BenchKey?

Your server verifies the HMAC signature in BenchKey-Signature with the signing secret. Timestamps must be within five minutes of now. For 24 hours after rotation, deliveries include signatures for both secrets.

What happens if our server is down?

BenchKey tries each delivery up to eight times with increasing waits. The Deliveries log shows each status. A webhook older than seven days switches off if, in the last seven days, at least five deliveries gave up and none were delivered. Press Enable to resume; events while off are not queued.

The waitlist is open for repair shops

Leave your email for access updates. Your name and shop name are optional.

Watch the product tour 3:34 Follow a repair from check-in to pickup in BenchKey