# How to create API keys and webhooks in Truffle

> Create a Truffle API key with Read, Write or Admin access, copy it once, regenerate or delete it, and set up a webhook with its events and a test.

Source: https://www.hiretruffle.com/how-it-works/guides/create-api-keys-and-webhooks  
Last verified against the product: 2026-10-05  
Time required: 10 min  
Every screenshot and label below was captured from the live product.

**Outcome.** By the end you have an API key with the access it needs, you know how to replace or remove it, and a webhook sends your system the events you chose.

## Before you start

- A paid Truffle plan. API access is not included with the free trial.
- The Owner or Admin role in Truffle. Integrations & API sits under WORKSPACE in Settings, which only owners and admins see.
- For a webhook, a public https address on your side that accepts HTTP POST requests.

## Steps

### 1. Request API access

Open **Settings**, choose **Integrations & API** under WORKSPACE, then the **API keys** tab. The first time, it shows **Request API Access**: **API access requires approval to ensure security and proper usage.** Choose **Request Access**. Truffle reviews the request, and the tab says to expect an answer within 1-2 business days. The **Webhooks** tab opens once access is approved, too.

### 2. Create your first key

Once access is approved, the tab reads **No API keys yet**. Choose **Create API Key**.

### 3. Name the key and choose its access

Give the key a **Name** and, if you like, a **Description**, so you can tell your keys apart later. Then choose its access. **Read Access** is ticked to start with: **View candidates, jobs, and screening results**. Add **Write Access** to **Create candidates, send invites, update records**. Choose **Create API Key**.

> Note: Give each key only the access it needs. The access belongs to the key, not to the person who made it.

### 4. Use Admin Access only when you need it

**Admin Access** is **Full access including webhooks and settings**. Ticking it greys out Read Access and Write Access, because Admin covers them.

### 5. Copy the key, shown once

**API Key Created** shows **Your API Key** with a copy button. Copy it and store it somewhere safe: you won't be able to see it again. Then choose **Done**.

### 6. Find the key in the list

Each key gets a card with its name, its access as **read**, **write** or **admin** pills, its description, the start of the key, and the date it was created and last used. A new key reads **Never used**.

### 7. Edit, regenerate or delete a key

The menu on a key card has **Edit**, **Regenerate Key** and **Delete**. Edit changes the name, description and access. The key itself stays the same.

### 8. Regenerate a key

Regenerate a key if you think it has leaked. **Regenerate API Key** warns that **This will invalidate the current API key.** Anything using the old key needs the new one straight away. Choose **Regenerate Key**.

### 9. Copy the new key

**New API Key Generated** confirms that **Your old key has been invalidated.** Copy the new key, which is also shown only once, and put it wherever the old one was used.

### 10. Delete a key

**Delete** opens **Delete API Key**. Type the key's name to confirm, then choose **Delete API Key**. Anything using the key loses access at once, and this cannot be undone.

### 11. Add a webhook

A webhook sends your system a message when something happens in Truffle. Open the **Webhooks** tab. With none set up it reads **No webhooks yet**. Choose **Add Webhooks**.

### 12. Set the URL and events

Give the webhook a **Name** and a **Webhook URL**: a public https address on your side. Under **Events**, choose what it receives. **Screening completed** is **Triggered when a candidate completes their screening**. **Résumé scored** is **Triggered when a candidate’s résumé finishes scoring**. Pick at least one. Truffle sends each event as an HTTP POST request with a JSON payload. Choose **Create Webhook**.

### 13. Check the webhook

The webhook gets a card with its name, an **active** pill, its URL, the date it was created and when it was last triggered. A new webhook reads **Never triggered**.

### 14. Edit, test or delete a webhook

The menu on a webhook card has **Edit**, **Test** and **Delete**. Edit changes the name, URL, events and description. Changing the URL affects anything that already relies on the webhook, so send a test after you save.

### 15. Send a test

**Test** sends a test event for the webhook's first event to your URL, with placeholder candidate details. **Webhook Test Successful** means Truffle queued the test. Check your own system to confirm it arrived.

### 16. Delete a webhook

**Delete** asks you to confirm. The webhook **will stop receiving events immediately**, and this cannot be undone. Choose **Delete Webhook**.

## FAQ

**Can I use the API on the free trial?**

No. API access is not included with trial accounts. On a paid plan, an owner or admin requests access from the API keys tab.

**Which access level should a key have?**

The least it needs. Read Access views candidates, jobs and screening results. Write Access creates candidates, sends invites and updates records. Admin Access is full access, including webhooks and settings.

**I lost an API key. Can Truffle show it again?**

No. A key is shown once, when you create or regenerate it. Regenerate the key and update anything that used the old one.

**What happens to the old key when I regenerate?**

It stops working. Anything still using it needs the new key.

**Which events can a webhook receive?**

Screening completed, when a candidate completes their screening, and Résumé scored, when a candidate's resume finishes scoring.

**Who can manage API keys and webhooks?**

Owners and admins. Members and viewers do not see Integrations & API.

## Exact labels in the product

These strings are captured from the live product and verified automatically, so they can be quoted directly:

`Integrations & API` · `WORKSPACE` · `API keys` · `Webhooks` · `Request API Access` · `API access requires approval to ensure security and proper usage.` · `We'll review your account and get back to you within 1-2 business days.` · `Request Access` · `No API keys yet` · `Create API Key` · `Name` · `Description` · `Read Access` · `View candidates, jobs, and screening results` · `Write Access` · `Create candidates, send invites, update records` · `Admin Access` · `Full access including webhooks and settings` · `access_read=false/disabled` · `API Key Created` · `Your API Key` · `Done` · `read` · `write` · `Never used` · `Edit` · `Regenerate Key` · `Delete` · `Regenerate API Key` · `This will invalidate the current API key.` · `New API Key Generated` · `Your old key has been invalidated. Update your applications with this new key.` · `Delete API Key` · `to confirm deletion` · `No webhooks yet` · `Add Webhooks` · `Create Webhook` · `Webhook URL` · `Screening completed` · `Triggered when a candidate completes their screening` · `Résumé scored` · `Triggered when a candidate’s résumé finishes scoring` · `Webhooks will be delivered as HTTP POST requests with JSON payloads.` · `active` · `Never triggered` · `Test` · `Webhook Test Successful` · `This webhook will stop receiving events immediately. This action cannot be undone.` · `Delete Webhook`

## Related

- https://www.hiretruffle.com/how-it-works/integrations
- https://www.hiretruffle.com/how-it-works/roles-and-permissions
- https://www.hiretruffle.com/how-it-works/limits-and-defaults
- https://www.hiretruffle.com/how-it-works/guides/connect-zapier
- https://www.hiretruffle.com/how-it-works/guides/connect-ashby

---

Truffle is an AI screening platform for small teams doing high-volume hiring: resume screening, one-way video interviews, and talent assessments, working with job boards like Indeed or an existing ATS. AI surfaces the evidence and you make every decision. Scores never reject a candidate; the only automatic rejection is a qualification rule the employer writes. https://www.hiretruffle.com
