---
updatedAt: 2025-09-16T01:31:27.000Z
agentTools:
  projectIndex: https://developers.gorgias.com/llms.txt
---

# Access Tokens (API Keys)

<HTMLBlock>{`
<blockquote class="callout callout_warn" theme="🚧">
  <h3 class="callout-heading empty"><span class="callout-icon">👉</span></h3>
  <p>Please remember that the API key authentication method can be used <strong>only for private apps</strong>. If you plan to build a public app you have to use OAuth2.</p></blockquote>
`}</HTMLBlock>

Each access token (or API key) is tied to a specific user and has the same permissions as the user that holds them. Requests made with an access token will act on behalf of a user and will have access to the resources their permissions allow. As an admin, you can easily generate and revoke your access token in the settings of your account.

**Example:** *If you use an Access Token for a user with an Observer Agent role, then you can only do the things that an Observer agent can. Learn more about roles[here](https://docs.gorgias.com/user/adding-team-members#user_permissions).*

## How do I get my API key?

1. Log in to your Gorgias account
2. Navigate to **Settings** → **REST API**
3. Click the **Create API key** button

Once you have your credentials, you can start performing requests directly from the [API documentation](https://developers.gorgias.com/reference/requests) .

## Request example

```curl
curl --request GET \
  --url https://your-customer-account.gorgias.com/api/account \
  --header 'Authorization: Basic base64encode(USERNAME:API_KEY)'
```

<HTMLBlock>{`
<blockquote class="callout callout_warn" theme="🚧">
  <h3 class="callout-heading empty"><span class="callout-icon">👉</span></h3>
  <p>Since we're using <a target="_self" href="https://datatracker.ietf.org/doc/html/rfc7617">HTTP Basic Authentication</a>, the <code class="rdmd-code lang- theme-light" data-lang="" name=""><button aria-label="Copy Code" class="rdmd-code-copy fa"></button><span class="cm-s-neo">USERNAME:API_KEY</span></code> pair has to be a <a target="_self" href="https://en.wikipedia.org/wiki/Base64">base64</a> encoded string. Note the <code class="rdmd-code lang-theme-light" data-lang="" name=""><button aria-label="Copy Code" class="rdmd-code-copy fa"></button><span class="cm-s-neo">:</span></code> between the <code class="rdmd-code lang- theme-light" data-lang="" name=""><button aria-label="Copy Code" class="rdmd-code-copy fa"></button><span class="cm-s-neo">USERNAME</span></code> and <code class="rdmd-code lang- theme-light" data-lang="" name=""><button aria-label="Copy Code" class="rdmd-code-copy fa"></button><span class="cm-s-neo">API_KEY</span></code> is a separator used to differentiate between the username and the password.</p></blockquote>
`}</HTMLBlock>