Step 1: Create a personal access token
The API authenticates every request with a Bearer token. In the dashboard, open User Settings → API Keys and create a personal access token. It starts withizap_pat_ and is shown only once, so store it in a secret manager or an
environment variable.
If API Keys is missing from your settings, your plan does not include the
REST API.
For third-party apps, use the OAuth 2.0 authorization-code + PKCE flow instead of
storing credentials. See Authentication.
Step 2: Call the API
Send the token as a Bearer header on every request:401 means the token was revoked or mistyped.
Step 3: Connect the Analytics MCP (optional)
Prefer to drive iZap from an AI client or agent? Point it at the iZap MCP server and call its tools directly. The client signs in over OAuth the first time it connects:Next steps
Authentication
Personal access tokens, the OAuth 2.0 flow, and discovery.
REST API
The resources iZap exposes and how to call them.