mTLS authentication
Certificate-based, mutual authentication - stronger than a bearer token for system-to-system connections.
For partner and system integrations that need machine-to-machine access with stronger authentication than a bearer token, CRMLeaf offers a certificate-secured (mTLS) public API endpoint - aimed at partner and system integrations rather than ad-hoc scripting.
Client presents certificate
CN=partner-erp.example.com
CRMLeaf verifies the client
Issued certificate · valid
Server presents certificate
Verified by the client
$ curl --cert partner.crt --key partner.key \
https://api.example.com/v1/contacts
HTTP/2 200 · mutual TLS established
Auth
Client certificate
Bearer token
Not required
How it's different
Certificate-based, mutual authentication - stronger than a bearer token for system-to-system connections.
Aimed at partner and system integrations, not ad-hoc scripting against your own account.
This sits alongside, not instead of, the personal access tokens used for lighter API and MCP access.
In detail
CRMLeaf's product-flow reference describes this as a separate mTLS certificate-authenticated API for B2B/machine-to-machine integrations, distinct from the REST API that authenticates via personal access tokens. It's positioned as an add-on that can be added to any plan.
Get certificate-secured, machine-to-machine access set up for your integration.