Treez APIs allow approved third-party integration partners and Treez dispensary customers to securely access Treez data and functionality.
As of October 1, 2026, Treez Support will no longer provision new legacy API Keys. New API access will be configured using Treez's V3 certificate-based authentication.
All existing integrations using legacy API authentication must migrate to V3 authentication before the November 1, 2026 deadline.
What's Changing?
Treez APIs are transitioning from legacy API Key authentication to a self-signed JSON Web Token (JWT) authentication model.
Under the new authentication model:
API Keys are no longer provisioned for new access requests.
Integrations authenticate using a registered security certificate and self-signed JWT.
Treez configures the appropriate Organization, Entity/dispensary, and API endpoint permissions for the certificate.
Treez provides the applicable Organization ID rather than issuing a new API Key for the dispensary.
A registered integration partner's certificate can be granted access to additional authorized Treez organizations and dispensaries without requiring a new certificate for each client.
Existing legacy authentication, hostnames, and routes will be deprecated on November 1, 2026. For technical details about V3 authentication, see the Treez API Authentication documentation.
Third-Party Integration Partners
Existing Treez integration partners should have already registered their security certificate with Treez as part of the V3 authentication migration.
If you're a Treez client requesting API access for an existing integration partner, you do not need to request or receive an API Key.
Instead, Treez Support will verify your authorization and configure the integration partner's existing certificate with access to your Treez environment.
Requesting Access for an Integration Partner
From Treez, select the Need Help? tab and choose Chat with Support.
Provide the following information:
API Integration Access Request
Customer URL:
Application / Integration Partner:
Customer Contact Name:
Customer Contact Email:
Integration Partner Contact Name:
Integration Partner Contact Email:
If provided by your integration partner, you may also include their existing Certificate ID.
What Happens Next?
Treez Support will:
Verify that the request was submitted by an authorized Treez user.
Identify the applicable Treez Organization and Entity/dispensary.
Locate and verify the integration partner's registered security certificate.
Configure the appropriate Organization, Entity, and API endpoint permissions for the certificate.
Provide the applicable Organization ID needed for the integration.
A new API Key will not be generated.
If Treez is unable to locate a registered security certificate for the integration partner, the partner will need to work with Treez to complete certificate registration before access can be provisioned.
Building Your Own Integration?
Treez customers may also use Treez APIs for internal integrations developed and maintained by their own organization.
Internal integrations are subject to the same V3 authentication requirements as third-party integrations.
If your organization currently uses a legacy Treez API Key for an internally developed integration, your development team must migrate the integration before November 1, 2026.
Registering an Internal Integration
Your development team will need to:
Review the Treez API Authentication documentation.
Generate the required RSA public/private key pair.
Provide the public security certificate to Treez for registration.
Identify the Treez Organization, Entity/dispensary, and API endpoints the integration requires.
Update the integration to use V3 authentication and the new Treez API hostname and resource paths.
Complete migration before November 1, 2026.
Never share your private key with Treez. Your private key is your organization's confidential credential and should be securely maintained by your development team. Only the public certificate should be provided to Treez.
Once the certificate is registered, Treez will configure the appropriate permissions and provide the information required to authenticate, including the applicable Organization ID.
November 1, 2026 Migration Deadline
All integrations using legacy Treez authentication must migrate to the new authentication and API path structure before November 1, 2026.
This includes:
Existing Treez integration partners
Custom integrations developed by Treez customers
Internal reporting or data integrations using Treez APIs
Other applications currently authenticating with legacy Treez API credentials
During the transition period, the legacy and new authentication methods and paths will continue to operate in parallel.
On November 1, 2026, legacy authentication, hostnames, and routes will be deprecated.
If your integration is still using a legacy API Key, do not wait until the deprecation date to begin migration. Your development or integration team should begin testing V3 authentication ahead of the deadline to allow time to resolve any authentication, permission, or endpoint configuration issues.
Additional Resources
Treez API Authentication
https://code.treez.io/reference/authentication
Treez API Reference
https://code.treez.io/reference/treez-api-reference
For questions about certificate registration, permissions, or API migration, contact Treez Support or [email protected].