How to Find Your API Key in Attio
Create an Attio access token in Workspace settings, with the exact scopes integrations need. A step-by-step guide, including the scope mistake that makes notes and tasks fail.
Attio calls its API credential an access token. You create it yourself in Workspace settings, and it never expires — but the scopes you tick when you create it decide what any connected tool can actually do. Getting those wrong is the most common reason an Attio integration connects successfully and then fails the first time it tries to write a note.
You need to be a workspace admin to create one.
Steps to create an Attio access token
Open your workspace settings In Attio, click your workspace name in the top-left corner, then choose Workspace settings.
Go to the Developers tab Select Developers in the settings menu. You can also go straight there: app.attio.com/settings/developers.
Create a new access token Click + New access token and give it a name that says what it is for, such as "Add to CRM".
Grant the scopes the integration needs Set the token's scopes before you save it. For a tool that writes contacts, companies, notes and tasks, grant Read-Write on record data, Notes and Tasks, plus user management: read so task assignees can be resolved.
Copy the token Copy the token and paste it into the tool you are connecting.
The scope mistake worth avoiding
Attio checks scopes per request, not at connection time. A token created with record access but without Read-Write Notes and Tasks will connect perfectly — and then return 403 requires scopes the first time something tries to log a note or create a task.
Because scopes are fixed when the token is created, you cannot widen them afterwards. If you discover a missing scope later, create a new token with the right scopes and reconnect. That is the whole fix, and it takes about a minute.

Connect Attio in seconds. Start enriching contacts
Add to CRM connects to Attio with OAuth or API key. Find verified emails and phone numbers on LinkedIn® and add them in one click.
Start Free TrialKeeping the token safe
Attio access tokens do not expire, so treat one like a password:
- Create a separate token per integration, so you can revoke one without breaking the others.
- Revoke tokens for tools you no longer use, from the same Developers page.
- Never paste a token into a shared document or a support ticket.

Start enriching Attio contacts for free
Add to CRM connects to Attio with OAuth or API key. Find verified emails and phone numbers on LinkedIn® and add them in one click.
Start Free TrialConnecting Attio to LinkedIn with Add to CRM
Add to CRM uses your Attio access token to add contacts straight from LinkedIn, Gmail and Outlook, with verified email addresses and phone numbers already filled in. Paste the token once on the connect screen and every profile you open can be added to Attio in one click — including notes and tasks, provided the token carries the scopes above.
Attio IntegrationAdd contacts to Attio from LinkedIn®
Enrich profiles with verified emails and phone numbers. Sync to Attio in one click.
Try Attio Extension7-day free trial · Cancel anytime
Save 4+ hrs / week on Attio data entry.
Find verified contact info for your prospects on LinkedIn®, Gmail, Outlook & company websites. Add them to your Attio with 1-click.