API keys

Make an API key that acts as you, choose what it can reach, test it, and change, rotate or revoke it.

An API key lets a program talk to Fondaro as you. Use one for your own script, for a developer you work with, or for an AI coding tool that builds something on your leads or listings. Admins find keys in Settings › Integrations › For developers › API keys; team members in Settings › Me › For developers › API keys.

Know what a key does

A key acts as you. It sees what you see in Fondaro and can do what you can do, and no more. If you are a team member, your key reaches your own leads. If you are an admin, it reaches the whole agency. Choosing less access for a key narrows it further; it never gives it more than you have.

If you leave the agency, your keys stop working. An older key, made before 4 October 2026, can keep reading and changing listings until an admin revokes it. An admin can revoke any key at any time, except keys set up by Fondaro.

Make a key

  1. Open the API keys page and choose New key.
  2. Give it a Name you will recognise, such as the tool or person that will use it.
  3. Choose Expires: in 30 days, 90 days, 1 year, on a date, or never. 90 days is the default. A key that expires cannot be forgotten about for years.
  4. Set the access for each area: Leads and CRM, Listings, Property search, Brochures and Documents. Each is No access, Read, or Read and write. Choose the least that does the job. Only admins can give Read and write on Listings.
  5. If the key will run on your own website, for example a listings widget, add the website under Allowed websites, one address per line, such as https://www.youragency.com. A key used in a web page needs Listings or Property search access at Read only, because anyone can read a key in a page. A key with Leads and CRM, Brochures or Documents access is for servers and cannot list websites.
  6. Choose Create API key.

You can have 10 active keys, and your organization 50. If you reach the limit, revoke a key you no longer use first. Keys made before 4 October 2026 do not work with the REST API: make a new one (rotating an older key does not change this). A key with Allowed websites does not work with it either, because the REST API is for servers.

The key appears once. Choose Copy key and save it somewhere safe, for example as FONDARO_API_KEY in your server's environment. You cannot see it again. If you lose it, rotate or replace the key.

Test a key

On the screen that shows your new key, choose Copy test call and paste it into a terminal. It asks Fondaro who the key acts as and shows your name, your agency and what the key may do. For a key with only Listings or Property search access, it asks for your listing counts instead. If you get an answer, the key works.

Under Use the API on the same page you find the base URL and links to the API reference and the guides. API overview walks through a first call.

Change a key's access or expiry

  1. In Your keys, open the actions menu on the key and choose Edit.
  2. Change the name, the access for each area, the expiry or the allowed websites.
  3. Choose Save.

Less access takes effect on the key's next call. Only the person a key acts as can give it more access, and an admin cannot give a team member's key more access than the member could use. To give someone else's key more, ask them, or create a new key.

You cannot edit a key that has expired or was revoked. A key you have just rotated is replaced by its new key: edit that one.

Rotate a key

Rotate when you think a key has leaked, or to swap secrets on a schedule.

  1. Open the actions menu on the key and choose Rotate, then Rotate key.
  2. Copy the new secret.
  3. Put the new secret wherever the old one is used.

The old secret keeps working for 24 hours, so nothing breaks while you switch. The new key has the same name, access, expiry and owner.

Revoke a key

Open the actions menu on the key, choose Revoke, then Revoke key. Anything that uses it stops working straight away. This cannot be undone.

See your team's keys

Everyone in the agency can see Agency keys, the keys other people made, but can change only their own. Admins can edit, rotate and revoke any key, except keys marked as set up by Fondaro.

The Owner column shows whose key it is. Left marks a key whose owner is no longer in the agency. Revoke it: an older key can still reach your listings. Expiring soon marks a key that is about to stop. Fondaro emails the owner about a week before a key expires; for an admin's key, or one whose owner left, the email goes to your agency's notification address.

Each key shows when and from where it was last used. Check this for activity you do not expect.

Keep keys safe

  • Keep keys in an environment variable or a secrets manager, never in code you share or a repository.
  • Give each tool its own key, with the least access it needs.
  • Never put a key with write access, or with Leads and CRM, Brochures or Documents access, in a web page.
  • Set an expiry, and revoke keys you no longer use.
  • Rotate at once if a key may have been seen by someone it should not be.

Connect an AI tool

To let an AI client such as ChatGPT or Claude Code work with your account, use Fondaro MCP instead: it signs you in through your browser and needs no key. To have an AI builder make your listings website, use Connect your website with AI at the bottom of the API keys page. Developers reading the technical side start at Authentication.