API - Packages and Endpoint Access

Starting with the October 2026 release, every API6 endpoint belongs to a package (a module on your subscription). Each time your API key calls an endpoint, the API checks that your subscription includes that endpoint's package. If it does not, the call is refused with an HTTP 403 response. Endpoints in packages you already have keep working exactly as before.

This article lists which package each endpoint belongs to, and where to add a package if your integration needs one you don't have yet.


Who This Affects

  • Requests made with an API key from Settings > API Keys. This includes Zapier, Event Hawk, and any custom integration built on API6.
  • The WordPress plugin and the IO mobile app are not affected.
  • API access as a whole still requires the WP/API package. Without it, API keys are rejected the same way they are today.

Packages at a Glance

Every endpoint needs the WP/API package. The endpoints in the rows below the first also need the extra package listed for them. For example, /tasks needs both WP/API and Sales CRM.

Package Your subscription includes it when Endpoints Add it
WP/API The API & WordPress module is active Too Many to List (Check Below) Activate API & WordPress
Sales CRM The Sales CRM module is active tasks, journals Activate Sales CRM
Workers The Workers module is active workers, workers_list, shifts_list, timeclock, positions, positions_list Activate Workers
Multi-Location You have purchased at least one location in addition to your primary location locations, locations_list Add a location
IO Phone At least one IO Phone number is set up on your account dial, text Add an IO Phone number

Always available:authenticate and me do not require any package, so an integration can always sign in and confirm which account it is connected to.


What a Refused Call Looks Like

When your subscription is missing the package for an endpoint, the API returns HTTP status 403 with a message that names both the package and the endpoint:

{"status":403,"message":"Your subscription does not include the CRM module required for the /tasks endpoint."}

Nothing is created or changed when a call is refused. Once the package is added, the next call goes through. You do not need a new API key.

A call to an endpoint name that does not exist returns HTTP 404 instead.


Endpoints by Package

WP/API

Activate API & WordPress

Inventory and pricing

Customers, leads and payments

Setup data and lookups

  • get_location_names
  • deliverymethods, deliverymethods_list
  • surfaces, surfaces_list
  • customertypes, customertypes_list
  • paymenttypes, paymenttypes_list
  • statuses, statuses_list
  • referrals, referrals_list
  • emailtemplates, emailtemplates_list
  • filters, filters_list, get_filter_names
  • get_report_names
  • keywords
  • stats (see Stats - Retrieve List)

Webhooks

  • automation_webhook_subscribe, automation_webhook_unsubscribe, get_sample_webhook_data, get_webhook_data (see Webhooks)

Tip for single-location accounts: if your quote form only needs the names of your locations, use get_location_names. It is part of WP/API. The full locations and locations_list endpoints require Multi-Location.

Sales CRM

Activate Sales CRM

Workers

Activate Workers

Multi-Location

Add a location

IO Phone

Add an IO Phone number


How to Add a Package

  1. Log in to your account as an admin user.
  2. Click the Add it link for the package in the table above. It opens Settings > Subscription at that package's section.
  3. Activate the package:
    • WP/API, Sales CRM, Workers: click Activate in that package's section.
    • Multi-Location: add a location in the Multi-Locations section.
    • IO Phone: add a phone number under Settings > IO Phone.
  4. Retry the API call. The package is recognized right away and your existing API key keeps working.

Checking Your Integration

  1. List the endpoints your integration calls. For Zapier, these are the actions and triggers in your Zaps. For a custom integration, they are the paths after /api6/ in its requests.
  2. Find each endpoint in the lists above and note its package.
  3. Compare those packages with the ones on your Subscription page, and add any that are missing.

Frequently Asked Questions

Do I need a new API key?
No. Existing keys keep working. The check is made on every call, against the account the key belongs to.

Do API key permissions still apply?
Yes. Packages decide which endpoints your account can use. API key permissions (set under Settings > API Keys) still decide what each key can read or change. A call has to pass both.

Do rate limits change?
No. The limits described in API - Setup Access stay the same.

I removed a package. What happens to my integration?
Calls to that package's endpoints start returning 403. Calls to endpoints in your other packages are not affected.


Related articles:API - Setup Access, API - Migration (API1-5 to API6)

Is this article helpful?
0 0 0