# Keap connection options: OAuth and API key

> Why OAuth is recommended, and how the API-key fallback works.

iTracker360 connects to Keap two ways. You can use either, or both together.

## OAuth (recommended)

OAuth is the standard, most reliable connection. Click **Connect** on the Keap integration and approve access in Keap. OAuth has higher rate limits and refreshes itself, so it keeps working without maintenance.

## API key (fallback)

You can also connect Keap with a service-account API key. When both are configured, iTracker360 tries OAuth first and falls back to the key if needed.

## A note on Keap's legacy API keys

Keap has **deprecated its old "Legacy API Keys"** — they no longer work. If you previously connected with one, reconnect using OAuth, or add a current service-account key from **Integrations → Connection**. Personal access tokens aren't suitable because they don't have the access needed to update every contact.

If your connection shows as failing, reconnecting with OAuth is the quickest fix.