Your financial data,one request away
Some tools you have to build yourself — the internal dashboard, the customer billing portal, the script that feeds your warehouse. Scoped CashFish API keys give your code the same records you see in the app, with only the permissions you grant.
Scale plan · $44/mo billed yearly ($529) · 4-day free trial · Full refund guarantee
The dashboard your team wants
is three numbers wide.
It never gets built, because getting those three numbers out means someone exporting a file every Monday until the Monday they forget.
A key with one job is easy to reason about, easy to rotate and easy to switch off — which is the whole argument for scopes.
The same records
you see in the app.
Read what you need, write what you must, and nothing beyond it. Each key carries only the scopes you tick, and can be pinned to an IP allowlist so it works from your servers and nowhere else.
Both directions, your call. Your code calls CashFish over HTTPS with exactly the scopes you grant per key — and a revoked key stops working immediately.
Up to 10 active keys per account, rate-limited to 500 requests per minute across the account — traffic arriving through Zapier counts against the same limit. A key is shown once at creation and stored hashed after that.
Five calls,
five narrow permissions.
What a modest internal tool actually asks for: the call, the scope it needs to be allowed to make it, and what comes back into the screen your team opens.
- invoice number
- client
- balance + due date
- money in, money out
- period totals
- closing position
- amount
- vendor + category
- receipt reference
- client id
- line items
- due date
- client id
- name
- first document seen
Each key carries only the scopes on its own row, is logged on every call with a timestamp and source IP, and can be revoked in settings at any time — the next request with it gets a 401 and the other keys carry on untouched.
Least privilege,
and a log to prove it.
Three things that are different once each tool holds its own key — with the numbers each one actually produces.
Set it up once.
Then let it run.
Name the key for its job, tick the scopes it needs, prove it against the sandbox, then point production at it.
Revocation takes effect on the next request — a 401, and nothing more. For a rotation with no downtime, deploy the replacement key first and revoke the old one afterwards. Data is protected with 256-bit encryption under SOC 2 Type II, ISO 27001 and GDPR, and every connection can be reviewed or disconnected from the Connection Health panel in settings.
One automation
is rarely the whole loop.
Duplicate detection runs across every source, so the same sale arriving through an automation and through an emailed receipt is recorded once. Accounting sync with QuickBooks and Xero is a one-way import into CashFish — your accounting file stays the ledger and is never written to. Shopify is in private beta and available by request only.
Scoped access,
on Scale and Teams.
Scale is the plan on this page because the custom API, its scopes and the request log belong to it, alongside webhooks, advanced forecasting, profitability by client and vendor and contract intelligence with renewal alerts.
API keys, scopes and the request log come with Scale and above; email and document extraction work from Starter.
4-day free trial · Full refund guarantee
Your subscription begins after the 4-day trial unless canceled beforehand. Full refund guarantee within the first 4 days.
Compare all plans →Build the tool your team keeps wishing existed. Scoped keys are included with Scale and Teams. Generate one in settings and make your first authenticated call today.
What people ask
before they wire up API Keys.

Start managing money smart.
Start managing money smart.
4-day free trial · Cancel anytime · Full refund guarantee
© 2026 CashFish Inc. All rights reserved.
CashFish
CashFish
CashFish

