Developers

The GoHighLevel API

The v2 API is free to use and allows 100 requests per 10 seconds and 200,000 per day, counted per Marketplace app per resource. Private Integration Tokens cover a single location and work on any plan. OAuth 2.0, which a Marketplace app requires, needs Agency Pro at $497 a month. v1 reached end of support on 31 December 2025 and still functions, unsupported.

Research-led reviewThe author has not used this product. Built from public sources.What this means

The author has not used this product. Everything here comes from six public sources: the maker's own site, its pricing and refund terms, its changelog, its support forum, counted complaints across recent public reviews, and a like-for-like comparison against the nearest alternatives. We never claim experience we do not have.

Which badge a page carries is enforced in the site build, not just in editing. A page cannot use first-hand language unless it has declared itself a real-use review, so the badge and the writing cannot drift apart. The full method

We earn a commission if you buy through links on this page, at no extra cost to you.How this works

You pay exactly what you would pay going direct. The maker pays us a share of their margin, not a surcharge on you.

We are never paid for a positive verdict, no maker sees a review before it publishes, and we publish verdicts recommending against products we could earn from. Commission rates never influence which products we cover or how we rank them. Full disclosure

The short version

  • The burst limit is the one that bites: 100 requests per 10 seconds, not per minute.
  • The daily limit is generous at 200,000, and it is per resource rather than overall.
  • OAuth is an Agency Pro feature. Build a Marketplace app on a cheaper plan and you stop at authentication.
  • HighLevel’s own pricing page and developer docs disagree about what Starter includes.
Try GoHighLevel free for 30 days

Affiliate link. We earn a commission if you subscribe, at no extra cost to you. 30 day free trial through HighLevel's Bootcamp offer, card required.

The actual rate limits

100 / 10 secis the burst limit per Marketplace app. The daily ceiling of 200,000 requests is rarely what stops people. This is.HighLevel developer documentation, checked 3 September 2026

Ten requests a second sounds comfortable until you write the first migration script. Pulling 5,000 contacts one page at a time, then fetching each contact's notes, is tens of thousands of calls, and a naive loop will hit the burst ceiling within seconds of starting. The fix is unglamorous: batch what the endpoints let you batch, sleep between pages, and read the rate limit headers rather than guessing.

The daily figure deserves a closer look because of three words in the documentation: it is 200,000 requests per day per resource. Contacts and opportunities are counted separately, so a job that touches several resources has more headroom than the single number suggests. That is unusually generous for a platform at this price, and it is worth knowing before you architect around a limit that is not there.

The v2 API in one table, read from HighLevel's developer documentation on 3 September 2026
Detail
Current versionv2. v3 is in development.
v1 statusEnd of support since 31 December 2025. Existing connections keep working, but get no support and no updates.
AuthenticationPrivate Integration Tokens for a single location, OAuth 2.0 for Marketplace apps and multi-location access.
Burst limit100 requests per 10 seconds, per Marketplace app.
Daily limit200,000 requests per day, per Marketplace app, per resource.
CostNo charge for the API itself. Usage-based charges still apply to anything it triggers.
The API itself costs nothing, but nothing it triggers is free. A workflow fired through the API that sends an SMS still draws from the agency wallet at the usual per-segment rate. The phone system page has those rates in full.

Which plan you need

API access by plan
PlanLevelWhat that means
Starter, $97BasicLocation API keys. No OAuth, no agency-level access.
Unlimited, $297BasicLocation API keys, the same as Starter despite the pricing page listing "Basic API Access" as an Unlimited feature.
Agency Pro, $497AdvancedOAuth 2.0 and agency API keys, which is what a Marketplace app needs.

This is the part that costs people money, because the decision looks like $97 against $497 and is really a question about what you are building. A private integration that syncs one client's contacts into a spreadsheet works fine on Starter. A public app that other agencies install needs OAuth, which needs Agency Pro, and there is no way to buy OAuth on its own.

Now the uncomfortable part. HighLevel's pricing page lists API Access among the features shared by every plan, then lists Basic API Access again as something the $297 tier adds over the $97 one. The developer documentation says something different again: Starter and Unlimited both get basic access with location API keys. Those statements cannot all be correct.

Where the two sources disagree, both read on 3 September 2026
SourceWhat it says
gohighlevel.com/pricingAPI Access listed in the feature set shared by every plan, and Basic API Access listed again as an Unlimited upgrade over Starter.
Help centre, API documentationStarter and Unlimited both get basic access with location API keys. Agency Pro adds OAuth 2.0 and agency keys.
We have not resolved this, because resolving it would mean guessing. If your build depends on API access at the $97 tier, confirm it with support in writing before you subscribe. That is a tedious thing to be told and a much cheaper thing than finding out in month two.

v1 is dead, and still running

v1 reached end of support on 31 December 2025. HighLevel's position is that existing connections keep working but receive no support and no updates, which is a softer statement than a shutdown date and a harder problem to plan around. Something that works today, has no maintainer, and could stop without notice is worse than something that is definitively switched off, because it never forces the migration.

If anything you own still talks to v1, the honest reading is that you are running on borrowed time with no warning system. v3 is in development, so the sensible target is v2 now rather than waiting to skip a version.

Start the 30 day GoHighLevel trial

Affiliate link. We earn a commission if you subscribe, at no extra cost to you. 30 day free trial through HighLevel's Bootcamp offer, card required.

Two ways to authenticate

Picking between them
MethodCoversUse it when
Private Integration TokenOne locationYou are automating your own account or a single client, and nobody else installs it
OAuth 2.0Multiple locations, with user consentYou are publishing a Marketplace app, or need agency-wide access

Most people reading this need the first one and think they need the second. A private token is a header on a request. OAuth means a consent screen, a token exchange, refresh handling and a Marketplace listing, which is a real project rather than an afternoon. Start private, and move to OAuth when someone other than you needs to install it.

Before you build

Things worth deciding before the first line of code
QuestionWhy it matters now
Does this need to survive a plan downgrade?OAuth is an Agency Pro feature, so a downgrade puts it at risk in a way a private token is not. HighLevel does not document what happens to a live OAuth app on downgrade, so confirm before you depend on it.
How will you handle 429s?The burst limit is easy to hit. Exponential backoff written on day one costs an hour; retrofitted, it costs a weekend.
Are you syncing or migrating?A one-off migration can be slow and sleepy. A live sync cannot, and needs the batching endpoints.
Could a webhook do this instead?Polling for changes burns the burst limit on requests that mostly find nothing changed. Webhooks push instead, which removes those requests entirely.
What happens when a workflow fires?API-triggered actions still draw from the wallet. Test with a small contact list, not the whole database.

The last one is worth repeating because it is the one that generates surprise invoices. A script that accidentally re-enrols 4,000 contacts into a workflow with an SMS step will send 4,000 texts, and the API will not stop you. HighLevel documents no dry-run or simulation mode, so test against a contact list of one.

If a native connection already exists you may not need the API at all, which the integrations page covers. For what the platform costs before any of this, see GoHighLevel pricing, and for whether the $497 tier earns its money beyond OAuth, the plan comparison.

OAuth needs the $497 plan

The trial runs on a full-featured account, which is the cheapest way to confirm the authentication method you need actually works before committing to a tier.

Start the GoHighLevel trial

Affiliate link. We earn a commission if you subscribe, at no extra cost to you. 30 day free trial through HighLevel's Bootcamp offer, card required.

If you are automating one business, not many

Worth saying plainly: Systeme.io's API is far more limited and it has no marketplace. What it has is a free plan, so if the automation you need is modest, you can build against it without paying anything to find out.

Start free on Systeme.io

Affiliate link to Systeme.io. We earn a commission if you later upgrade, at no extra cost to you. No card required, and the free plan does not expire.

The middle option on integrations

ClickFunnels has a smaller API surface than GoHighLevel and no sub-account model, so it is the wrong tool for agency automation. For one business with a few webhooks, it is enough.

Start the ClickFunnels trial

Affiliate link. We earn a commission if you subscribe, at no extra cost to you. 14 day trial, then $97 a month with a 30 day money-back guarantee.

Common questions

What are the GoHighLevel API rate limits?

A burst limit of 100 requests per 10 seconds and a daily limit of 200,000 requests, both counted per Marketplace app, with the daily figure applying per resource. Responses carry X-RateLimit headers so you can track usage rather than guess.

Is the GoHighLevel API free?

Yes, there is no charge for API calls themselves. Anything the calls trigger is still billed as usual, so an API-fired workflow that sends SMS draws from the agency wallet at the normal per-segment rate.

Which GoHighLevel plan do I need for API access?

Private Integration Tokens for a single location work on any plan. OAuth 2.0 and agency API keys, which a public Marketplace app needs, require Agency Pro at $497 a month. Note that HighLevel’s pricing page and help centre describe Starter’s access differently, so confirm with support before subscribing on that basis.

Is the GoHighLevel v1 API still working?

It reached end of support on 31 December 2025. Existing connections continue to function but receive no support and no updates, and no shutdown date has been published. Anything still on v1 should be migrated to v2.

What is the difference between a Private Integration Token and OAuth?

A private token authenticates one location and is a single header on a request. OAuth 2.0 authenticates across multiple locations with user consent, and is what a Marketplace app installed by other agencies requires. Most internal automation only needs the private token.

Can I avoid the rate limit by polling less?

Better to not poll at all. Webhooks push changes to you as they happen, so replacing a polling loop with a webhook removes the repeated requests that were consuming the limit rather than merely spacing them out.

Last reviewed September 3, 2026