Inbound Integration Keys
Create and manage Inbound integration keys for sending conversion events to CleanClicks from CRMs, automation platforms, and custom backends.
Inbound integration keys let you send conversion events to CleanClicks from external systems: CRMs, marketing automation platforms, webhook-based integrations, or custom backends.
Accessing Inbound Integration Keys
- Go to Configuration in the sidebar
- Select your domain
- Click the Inbound keys tab
Plan Limits
Each plan allows a fixed number of inbound integration keys per domain:
| Plan | Maximum inbound integration keys per domain |
|---|---|
| Signal | 5 |
| Clarity | 10 |
Once you reach the limit, the create button is disabled and the tab tells you to revoke an existing key or upgrade your plan.
Creating an Inbound Integration Key
- Click Create Inbound Integration Key
- Give it a descriptive name (e.g., "Zapier Integration," "CRM Webhook," "Backend Server")
- Click Create
The full inbound integration key is displayed once. Copy it immediately and store it securely. After you close the dialog, you'll only see a masked version.
Inbound integration keys use a cc_ prefix followed by a random string. Example: cc_a1b2c3d4e5f6...
Using an Inbound Integration Key
Include the inbound integration key in the X-CC-Api-Key header when sending events to the CleanClicks inbound endpoint:
POST https://cleanclicks.yourdomain.com/__cc/inbound
Content-Type: application/json
X-CC-Api-Key: cc_your_api_key_here
{
"email": "customer@example.com",
"event": "purchase",
"value": 99.99,
"currency": "USD"
}
See Inbound Webhooks for the full API reference and payload format.
Managing Inbound Integration Keys
Viewing Keys
The Inbound keys tab lists the active keys for the selected domain in four columns:
- Name: the label you gave it
- Key: the first few characters, for identification (the rest stays masked)
- Created: the date you created the key
- Last Used: the date the key last authenticated a request, or
Never
Revoking a Key
If a key is compromised or no longer needed:
- Find the key in the list
- Click Revoke
- Confirm
Revoked keys immediately stop working, and any system still using one receives authentication errors. A revoked key drops off the list and cannot be restored from the dashboard. If you need access again, create a new key and update your integration.
Security Best Practices
- One key per integration. If you use Zapier and a custom backend, create separate keys. This lets you revoke one without affecting the other.
- Never put Inbound integration keys in client-side code. Inbound integration keys are for server-to-server communication only. They should never appear in JavaScript, HTML, or any code that runs in a browser.
- Rotate keys periodically. Create a new key, update your integration, then revoke the old key.
- Use descriptive names. When you need to revoke a key six months from now, you'll want to know which integration it belongs to.
Next: Connections Overview