Skip to main content
This guide gets you from zero to your first authenticated API call. You’ll need an iZap account on the environment you’re targeting (production or staging), on a plan that includes the REST API.

Step 1: Create a personal access token

The API authenticates every request with a Bearer token. In the dashboard, open User Settings → API Keys and create a personal access token. It starts with izap_pat_ and is shown only once, so store it in a secret manager or an environment variable.
If API Keys is missing from your settings, your plan does not include the REST API.
For third-party apps, use the OAuth 2.0 authorization-code + PKCE flow instead of storing credentials. See Authentication.

Step 2: Call the API

Send the token as a Bearer header on every request:
A personal access token does not expire; it stays valid until you revoke it from the same screen. A 401 means the token was revoked or mistyped.

Step 3: Connect the Analytics MCP (optional)

Prefer to drive iZap from an AI client or agent? Point it at the iZap MCP server and call its tools directly. The client signs in over OAuth the first time it connects:
See Analytics MCP for the full tool catalog and for server-to-server agents that can’t sign in interactively.
Want the scaffolding done for you? npx @izap/wizard writes a working REST, MCP, webhook, or SSE client into your project. See the setup wizard.

Next steps

Authentication

Personal access tokens, the OAuth 2.0 flow, and discovery.

REST API

The resources iZap exposes and how to call them.