Get started
Authentication
Create a workspace API key, send it as a bearer token, and handle rate limits and errors.
API keys
Every API request carries a workspace API key. A key belongs to one workspace and can do what the API allows for that workspace, whoever created it. Keys look like cuedm_ followed by 43 characters.
Create a key
In Settings → Integrations, under API keys, choose Create key. Name it after what will use it, such as “Zapier” or “Warehouse sync”, so you know which one to revoke later.
Copy it once
CueDM shows the key once and stores only a hash of it. If you lose it, revoke it and create a new one.
Keep it on the server
Put it in an environment variable or your secrets manager. Never put it in a web page, a mobile app or a public repository: anyone with the key can manage your workspace's webhooks.
Studio plan
API keys are part of Studio. If the workspace moves to another plan, its keys are kept but refused with a 403. They work again as soon as the workspace is back on Studio. Webhooks set up in Settings keep working on every plan.
A workspace can have up to 10 active keys. The list in Settings shows when each key was last used (to the minute). Revoking a key stops it at once.
Sending the key
Send the key as a bearer token in the Authorization header. Keys in the query string or body are ignored.
curl https://cuedm.com/api/v1/me \
-H "Authorization: Bearer cuedm_…"A missing, mistyped or revoked key gets a 401 with a WWW-Authenticate: Bearer header. Requests with a bad key never count against a rate limit.
Rate limits
Each key can make 120 requests a minute. The window starts with the key's first request and resets a minute later. Each key has its own limit, so two keys in the same workspace get 120 each.
Over the limit, the API answers 429 with these headers. Wait for Retry-After seconds, then try again.
Retry-Afterseconds- How long until the window resets.
X-RateLimit-Limitinteger- Requests allowed per minute (120).
X-RateLimit-Remaininginteger- Requests left in this window.
X-RateLimit-ResetUnix seconds- When the window resets.
A normal Zapier or Make connection sends a few requests an hour. If you reach the limit, something is probably calling the API in a loop, often the sample endpoint.
Errors
Errors use ordinary HTTP status codes. The body always has success: false and an error you can show to a person. Validation errors may also include details.
{
"success": false,
"error": "Send a workspace API key as Authorization: Bearer cuedm_…"
}400Bad Request- The body is not valid JSON, or a field is missing or wrong. The error says which.
401Unauthorized- The key is missing, mistyped or revoked.
403Forbidden- The key is valid but the workspace is not on Studio.
404Not Found- No such resource, for example an unknown event name.
429Too Many Requests- Rate limited. Retry after the Retry-After header.
5xxServer error- Something failed on our side. Retry with backoff; if it continues, email support.
Stuck, or something here is wrong? Email support@cuedm.com and a person will answer.