Independent HighLevel affiliate publication. We may earn a commission if you buy through links on this page, at no extra cost to you.

Practical guide

GoHighLevel API: plans, tokens, rate limits and where the docs are

Last materially reviewed 2026-10-03

Quick answerYes. GoHighLevel has a public REST API (API 2.0) with OAuth 2.0 and Private Integration Tokens, limited to 100 requests per 10 seconds and 200,000 per day. Advanced access needs Agency Pro at $497 a month.

Does GoHighLevel have an API? Yes, API 2.0

Yes. GoHighLevel has a public REST API, and the current supported version is API 2.0. Requests go to the base address services.leadconnectorhq.com, and the official reference lives at marketplace.gohighlevel.com/docs. HighLevel's support article says its older Stoplight documentation is deprecated, so that marketplace site is the one to bookmark.

The older V1 API reached end of support on 31 December 2025. HighLevel says existing V1 connections keep working but receive no fixes or updates, so anything new should be built on API 2.0. The same support article mentions a V3 that is still in development, with no date given.

This page is based on HighLevel's published documentation, read on 3 October 2026. We have not built against the API ourselves.

Basic and Advanced API access by plan

HighLevel splits API access into two tiers. Its API support article puts Basic access on the Starter and Unlimited plans and Advanced access on Agency Pro only.

GoHighLevel API access by plan, as read on 3 October 2026
PlanMonthly priceAPI tierWhat the tier covers
Starter$97Basic (per the API support article)Location-level access for one sub-account at a time
Unlimited$297BasicLocation-level access for one sub-account at a time
Agency Pro$497AdvancedOAuth 2.0 and agency-level keys that reach many sub-accounts

One caution. The public pricing page lists Basic API Access for the first time on the Unlimited card and does not show it in the Starter bullet list. The two official pages disagree, so if you plan to use the API on Starter, confirm it during the 14-day trial before you rely on it. The full plan breakdown is on our GoHighLevel pricing page.

OAuth 2.0 and Private Integration Tokens

There are two ways to authenticate, and the right one depends on who will use what you build.

GoHighLevel API authentication methods
MethodMeant forHow it works
Private Integration TokenInternal tools and single-location integrationsA fixed token created under Settings, then Private Integrations. You pick the scopes it may use and send it as a Bearer token.
OAuth 2.0Marketplace apps and anything used across many accountsThe account owner approves your app in a consent flow. Access tokens last one day and refresh tokens last one year.

For a Private Integration Token, the documented steps are:

  1. Open Settings and choose Private Integrations.
  2. Create a new integration and give it a name.
  3. Select only the scopes the integration needs.
  4. Copy the token and store it somewhere safe.
  5. Send it in the Authorization header with the Version header shown in the docs, which read 2021-07-28 on the token page.

HighLevel recommends rotating these tokens every 90 days. During rotation the old and new token both work for seven days, and a token can be expired at once if it leaks.

Published rate limits and webhooks

The limits are published. API 2.0 allows a burst of 100 requests every 10 seconds and 200,000 requests per day. Both limits are counted per Marketplace app per resource, where a resource is a single location or a company.

Responses carry headers that show where you stand, including X-RateLimit-Max, X-RateLimit-Remaining and X-RateLimit-Daily-Remaining. A nightly sync that loops over every contact should read those headers and slow down instead of retrying blindly.

Webhooks are available for real-time events. The developer docs describe more than 50 event types. To receive them you register an app, set a webhook address, add the scopes for the events you want and complete the OAuth authorization. HighLevel also documents SDKs for TypeScript or JavaScript, Python and PHP.

Who should use the API, and what to use instead

The API suits a business with a developer who needs to push leads in from a custom form, sync contacts with another system or build reports HighLevel does not offer. It suits agencies on Agency Pro that want one app working across many client sub-accounts.

It is a poor fit if nobody on the team writes code. HighLevel states that its support team does not audit setup code or give developer consulting, and it points developers to a separate developer portal and community Slack. In that case a no-code connector such as Zapier or Make is the better route, and our guide to GoHighLevel integrations covers those options.

If the goal is to let an AI assistant read and update the CRM, you may not need to write API code at all. HighLevel runs an official MCP server on the same infrastructure, explained in does GoHighLevel have an MCP.

Sources used for this page

The facts above come from the pages below, read on 3 October 2026. We have not used these products hands-on. Prices and terms change, so confirm them on the vendor's site before you buy.

  1. HighLevel API Documentation (support article) — Vendor documentation · help.gohighlevel.com · checked 2026-10-03
  2. HighLevel API developer documentation — Vendor documentation · marketplace.gohighlevel.com · checked 2026-10-03
  3. HighLevel API OAuth FAQs — Vendor documentation · marketplace.gohighlevel.com · checked 2026-10-03
  4. Private Integrations Token (developer docs) — Vendor documentation · marketplace.gohighlevel.com · checked 2026-10-03
  5. Authorization (developer docs) — Vendor documentation · marketplace.gohighlevel.com · checked 2026-10-03
  6. HighLevel Pricing — Vendor pricing page · gohighlevel.com · checked 2026-10-03