Start GoHighLevel through Revset: 30-day trial + we build your first automation with you, free →
Book a call
AI & features

GoHighLevel APIAccess, Authentication, Rate Limits and When You Need It

Checked October 11, 2026Arsalan Zaffar11 min read

HighLevel API

v2
  • Included on every plan
  • Private Integration Tokens and OAuth 2.0
  • Webhooks for real-time events
  • 100 requests / 10 s, 200,000 / day OAuth
  • API v1: end of support

Key facts

The GoHighLevel API at a glance

Checked October 11, 2026 · HighLevel: API documentation

Current version
API v2
Starter / Unlimited
Basic API access
Agency Pro
Advanced API access
Auth
Private Integration Token or OAuth 2.0
Burst limit
100 requests per 10 seconds
Daily limit
200,000 requests per day
API v1
End of support 31 December 2025

Plans

GoHighLevel API access by plan

API access on each GoHighLevel plan
CompareStarter$97/moUnlimited$297/moAgency Pro$497/mo
API
API v2 accessBasicBasic
Private Integration Tokens
SaaS Configurator public APIs

Basic vs Advanced from HighLevel’s API documentation article (modified 18 August 2026). HighLevel doesn’t publish an endpoint-by-endpoint split, so check the scopes in the docs for your plan.

Versions

API v1 vs v2: what changed

HighLevel API v1 vs v2
Comparev1 (legacy)v2
Status
SupportedEnded 31 December 2025
New keys can be created
New endpoints added
Authentication
Static API key
Scoped tokens (PIT or OAuth)

Authentication

Private Integration Token vs OAuth 2.0

Building for your own account? Use a Private Integration Token. Building an app others install? Use OAuth.

Private Integration Token vs OAuth 2.0 in HighLevel
ComparePrivate Integration TokenOAuth 2.0
Use it for
Your own scripts, n8n, internal tools
Marketplace apps installed by others
How it works
Created inMarketplace developer portal
ScopesRequested at install
Token lifetimeAccess token expires daily; refresh it
How manyPer app install

Setup

How to get a GoHighLevel API token

  1. Step 1

    Open Private Integrations

    In the agency or sub-account Settings. Agency owners can limit who may create them.

  2. Step 2

    Create an integration

    Name it after the tool that will use it, e.g. “n8n – lead sync”.

  3. Step 3

    Pick only the scopes needed

    Read-only where possible. Scopes can be edited later without a new token.

  4. Step 4

    Store the token safely

    In a secret manager or your tool’s credentials store, never in a shared doc. Set a 90-day rotation reminder.

HighLevel guide: Private Integrations: everything you need to know (modified 29 September 2026).

Limits

HighLevel API rate limits

Limits are per Marketplace app per resource. Installing on more sub-accounts gives each one its own budget.

Key facts

API v2 rate limits

Checked October 11, 2026 · HighLevel: Rate limits

Burst (OAuth)
100 requests per 10 seconds
Daily (OAuth)
200,000 requests per day
Counted per
App × sub-account or agency
Sandbox PIT
25 requests per 10 seconds; 10,000 requests per day
Production PIT
Standard limits by plan (no separate figure published)

Headers to read on every response

  • X-RateLimit-Limit-Daily
  • X-RateLimit-Daily-Remaining
  • X-RateLimit-Interval-Milliseconds
  • X-RateLimit-Max
  • X-RateLimit-Remaining

Real time

Webhooks: events in and out

Don’t poll the API for changes: let HighLevel tell you.

App webhooks

Marketplace apps subscribe to events listed in the API docs.

Workflow webhooks

Inbound webhook trigger and custom webhook action, no app needed. See integrations.

Use cases

What people build with the GoHighLevel API

Two-way CRM sync

Keep contacts in step with another CRM or an ERP.

Reporting warehouse

Push deals and payments into BigQuery or a spreadsheet for agency-wide reports.

Sub-account provisioning

Create and configure client accounts from your own signup flow.

Custom portals and apps

Client dashboards or mobile apps on top of HighLevel data.

AI agents

Let AI tools read and update the CRM, or use HighLevel’s MCPMCP: Model Context Protocol: a standard way for AI assistants to use a software's tools and data. server. See GoHighLevel AI.

Marketplace apps

Build an app other agencies install, and sell it.

Decide

Do you actually need the API?

Most businesses don’t. Check these first.

  • A native integration or Marketplace app already does it → no API needed
  • Low-volume link to another app → Zapier’s LeadConnector app
  • Another tool needs to start a workflow → inbound webhook
  • Two-way sync, bulk data or a custom app → yes, use the API
  • Selling an app to other agencies → yes, OAuth Marketplace app

Security

API security habits

  • One token per tool, named after it
  • Least-privilege scopes
  • Rotate every 90 days (7-day overlap)
  • Rotate and expire immediately if a token leaks
  • Restrict who can create Private Integrations (Roles & Permissions)
  • Never paste tokens into client-side code or shared docs

What users ask

GoHighLevel API questions from Reddit, answered

  • “Where’s the real API documentation?”

    Developers struggle to find current docs.

    Fix Use marketplace.gohighlevel.com/docs (v2). Old v1 pages and third-party copies are out of date.

    Source: r/gohighlevel: GHL API documentation
  • “My API integration keeps failing”

    Usually auth or scope errors.

    Fix Check you’re on v2 with a PIT that has the right scopes, and that you send the location (sub-account) ID the endpoint expects.

    Source: r/gohighlevel: Need help with API integration
  • “HighLevel just dropped an MCP server”

    Builders discuss using AI tools with HighLevel data.

    Fix MCP is the quickest way to let AI assistants work with HighLevel. Use the API when you need exact, repeatable automation.

    Source: r/gohighlevel: HighLevel MCP server

Expert take

When I reach for the GoHighLevel API

GoHighLevel API FAQ

Does GoHighLevel have an API?
Yes. API v2 is included on every plan: Basic API access on Starter and Unlimited, Advanced API access on Agency Pro ($497/month). Documentation is at marketplace.gohighlevel.com/docs.
Where is the GoHighLevel API documentation?
At marketplace.gohighlevel.com/docs/, which has a version switcher, endpoint references, OAuth guides, webhook events and rate limits. HighLevel also publishes Python and PHP SDKs.
How do I get a HighLevel API key?
Create a Private Integration in Settings (agency or sub-account), choose the scopes it needs and copy the token. Legacy v1 API keys can no longer be created.
What is the difference between API v1 and v2?
v1 used static location API keys and reached end of support on 31 December 2025: existing calls still work, but it gets no updates. v2 uses OAuth 2.0 or Private Integration Tokens with scopes, and is where all new endpoints are added.
What is a Private Integration Token (PIT)?
A scoped token for server-to-server access to the v2 API, created in Settings. Up to 20 per agency and per sub-account. Rotate it every 90 days; the old token keeps working for 7 days during a rotation.
Should I use OAuth or a Private Integration Token?
Use a Private Integration Token for your own account’s internal tools and scripts. Use OAuth when you build a Marketplace app that other agencies or sub-accounts install.
What are the HighLevel API rate limits?
For OAuth apps on API v2: 100 requests per 10 seconds and 200,000 requests per day, counted per app per sub-account or agency. Read the X-RateLimit headers rather than counting yourself. Sandbox PITs are limited to 25 requests per 10 seconds and 10,000 requests per day.
Does GoHighLevel have webhooks?
Yes. Marketplace apps can subscribe to real-time webhook events (see the docs), and workflows have an inbound webhook trigger and a custom webhook action.
Can I use the API with n8n or Make?
Yes. Call the v2 endpoints with a Private Integration Token from n8n’s HTTP Request node or Make’s HTTP module. HighLevel’s MCP server also works with n8n.
How do I monitor failed webhook calls?
Check the workflow execution log for failed custom webhook actions (they retry with backoff, then fail), log every inbound payload on your side, and alert on non-200 responses.
Can webhooks trigger AI agent actions?
Yes. An inbound webhook can start a workflow that uses HighLevel’s AI actions, and AI agents can call external tools through MCP connectors.

Footnotes

  1. HighLevel “API Documentation” (modified 18 August 2026), “Private Integrations” (modified 29 September 2026), developer portal rate limits and sandbox PIT pages, SDK and Developer Marketplace articles. Plan prices from gohighlevel.com/pricing. Checked October 11, 2026. Back to text

Build on HighLevel, or let us

Start a 30-day trial with API access, or ask our team to build the integration.

  • 30 days free

    HighLevel’s official bootcamp offer.

  • API v2 on every plan

    Basic or Advanced by plan.

  • Your first automation, built free

    Signed up through Revset? Book a free 30-minute Launch Call. We build your first lead follow-up automation with you, live, so new leads get a text and email the moment they come in.

  • Or hire an expert

    Integrations built and documented.