Developers · Public API · mTLS

A certificate-secured public API for partner integrations

For partner and system integrations that need machine-to-machine access with stronger authentication than a bearer token, CRMLeaf offers a certificate-secured (mTLS) public API endpoint - aimed at partner and system integrations rather than ad-hoc scripting.

  • ✓Free trial
  • ✓No credit card
  • ✓Free onboarding
Partner integration · mTLSMachine-to-machine
  1. 1

    Client presents certificate

    CN=partner-erp.example.com

    ✓
  2. 2

    CRMLeaf verifies the client

    Issued certificate · valid

    ✓
  3. 3

    Server presents certificate

    Verified by the client

    ✓

$ curl --cert partner.crt --key partner.key \

https://api.example.com/v1/contacts

HTTP/2 200 · mutual TLS established

Auth

Client certificate

Bearer token

Not required

How it's different

Built for machine-to-machine, not scripting

mTLS authentication

Certificate-based, mutual authentication - stronger than a bearer token for system-to-system connections.

Partner & system integrations

Aimed at partner and system integrations, not ad-hoc scripting against your own account.

Separate from personal tokens

This sits alongside, not instead of, the personal access tokens used for lighter API and MCP access.

In detail

Where this fits

CRMLeaf's product-flow reference describes this as a separate mTLS certificate-authenticated API for B2B/machine-to-machine integrations, distinct from the REST API that authenticates via personal access tokens. It's positioned as an add-on that can be added to any plan.

  • mTLS
  • B2B integrations
  • Add-on

Built in

  • Certificate-secured (mTLS) endpoint, not bearer-token auth
  • Built for partner and system integrations
  • Add-on, available on any plan
FAQ

Frequently asked questions

Talk to us about partner-grade access

Get certificate-secured, machine-to-machine access set up for your integration.