Docs › Settings
API keys, webhooks and OAuth apps
Connect scripts, automation tools and your own apps to Daykite — safely, with only the access they need.
Settings → API keys & webhooks is for connecting Daykite to things you build or run. For ready-made recipes with Zapier, Make and n8n, start with Connect other tools instead.
| Tool | Direction | Use it for |
|---|---|---|
| API key | Your script → Daykite | A script, CLI tool or self-hosted automation calling the API |
| Webhook | Daykite → your server | Hearing about changes the moment they happen |
| OAuth app | Another person's Daykite → your app | An app you're building that other people connect to their own Daykite |
Full endpoint reference: the Developers page.
API keys
- Under API keys, name the key — what's it for?
- Tap each scope it needs, and nothing more.
- Choose Live or Test.
- Create key. Copy it now — it's shown once.
Each key is listed with its first characters, its scopes, and when it was last used. Revoke stops it immediately.
Scopes:
| Area | Scopes |
|---|---|
| Events | events:read · events:create · events:update · events:delete |
| Calendars | calendars:read · calendars:write |
| Availability | availability:read |
| Tasks and projects | tasks:read · tasks:write · projects:read · projects:write |
| Spaces and organizations | spaces:read · organizations:read |
| Routines | routines:read · routines:write |
| Bookings | bookings:read · bookings:write |
| Notifications | notifications:read · notifications:write |
| Apps | devices:write · sync:read |
A key can never create more keys, register apps or set up webhooks — those always need you, signed in. A leaked key can't be used to give itself more access.
Some endpoints have no scope and take no key: the assistant, the planner, goals, insights, your settings and anything
else built for the DayKite apps. Those need a session — you, signed in — and answer 403 session_required to a key.
The apps get one by signing in; there's nothing to set up.
curl "https://daykite.com/api/v1/events?from=2026-09-14T00:00:00Z&to=2026-09-21T00:00:00Z" \
-H "Authorization: Bearer YOUR_API_KEY"
Webhooks
- Under Webhooks, name it and paste your Endpoint URL.
- Choose the events to send.
- Create webhook, and copy the signing secret — shown once.
| Events |
|---|
event.created · event.updated · event.cancelled |
task.created · task.updated · task.completed · task.assigned · task.due_changed · task.deleted |
booking.created · booking.cancelled · booking.rescheduled |
routine.created · routine.updated · routine.deleted · routine.period.completed · routine.period.skipped |
Beside each webhook: Send a test (shows the status and how long your server took), Disable / Enable, and
delete. Every delivery is a signed JSON POST; check the X-Calendar-Signature header as described in
Checking a request came from Daykite.
Deliveries that don't get a 2xx are retried up to five more times.
OAuth apps
For an app other people will connect to their own Daykite, so they never hand you an API key.
- Under OAuth apps, enter your application's name and Redirect URI.
- Choose the scopes it may ask for.
- Register it, and copy the client secret — shown once — alongside the client ID.
People who connect see your app's name and exactly what it's asking for before they agree.