What your SuiteCRM needs before an AI app can use it.

Four things, all standard parts of SuiteCRM 7.10 and newer and SuiteCRM 8. An administrator can check them in about ten minutes. Nothing gets installed.

To connect SuiteCRM to Claude or another AI app through SuiteBrain AI, you need SuiteCRM 7.10 or newer (or any SuiteCRM 8), its V8 API reachable at your CRM’s public address, the API’s OAuth2 key pair in place, and one Password Client created under Admin, OAuth2 Clients and Tokens. Each person then signs in with their own SuiteCRM login.

Does my SuiteCRM have the V8 API?

If it is SuiteCRM 7.10 or newer, yes. SuiteCRM 8 serves it under /legacy/Api; SuiteCRM 7 serves it under /Api. SuiteBrain AI tries both on its own, so you give it the address you use to sign in to the CRM and nothing else.

If setup says it found no V8 API, the address is usually not the CRM’s base address. On some SuiteCRM 8 servers the web root points at the install folder rather than its public folder, and the working address ends in /public. Use the one your browser shows on the login page.

Are the OAuth2 keys in place?

The V8 API signs its tokens with a key pair, and it will not issue a token without one. SuiteCRM’s own guide puts them in Api/V8/OAuth2 under the SuiteCRM root (on SuiteCRM 8, public/legacy/Api/V8/OAuth2), with permissions 600 or 660 and owned by the web server user. If they are missing, the guide generates them like this:

openssl genrsa -out private.key 2048
openssl rsa -in private.key -pubout -out public.key
sudo chmod 600 private.key public.key
sudo chown www-data:www-data p*.key

Commands from SuiteCRM’s JSON API setup guide, checked September 2026. Use your own web server user if it is not www-data.

Which OAuth2 client should I create?

  1. Sign in to SuiteCRM as an administrator and open Admin. On SuiteCRM 8 it is in the user menu, top right.
  2. Under OAuth2 Clients and Tokens, choose New Password Client.
  3. Give it any name, type a secret you choose, and save. Copy the generated ID and the secret into SuiteBrain AI’s setup.

Not New Client Credentials Client. A client credentials token carries no user, so SuiteCRM would have nobody to apply roles to. A Password Client lets each person sign in as themselves, which is what makes their SuiteCRM permissions apply to everything the assistant does.

Why does SuiteCRM say “Client authentication failed” when the secret is right?

Because SuiteCRM validates the client against the grant it is used with. A Client Credentials Client offered to a password sign-in is refused with exactly the message a wrong secret gives. It cost us real debugging time, so SuiteBrain AI’s setup now checks which case you are in and says “this is a Client Credentials client, create a Password Client” instead of leaving you to guess.

What happens when someone asks for something their role does not allow?

SuiteCRM refuses it, and the assistant says so. The V8 API reports an access denial as HTTP 400 with an AccessDeniedException detail rather than a 403; SuiteBrain AI reads that as “not permitted” and tells the person, instead of retrying or guessing. Nobody sees or changes more through the assistant than they could in the CRM.

Does the CRM need to be on the internet?

For the hosted service, yes: it calls your SuiteCRM at its public address and refuses private network addresses. Serve the CRM over HTTPS: sign-ins pass through that connection. If your CRM must stay inside your network, the Business plan includes a self-hosted licence and Enterprise runs air-gapped. See plans.

Questions admins ask

Which SuiteCRM versions have the V8 API?
SuiteCRM 7.10 and newer, and every SuiteCRM 8 release. SuiteCRM 8 serves it under /legacy/Api and SuiteCRM 7 under /Api. Older versions do not have it, so no V8 connector can reach them.
Why does SuiteCRM say "Client authentication failed" when the secret is correct?
Because the client is the wrong type. SuiteCRM checks the client against the grant it is used with, so a Client Credentials Client offered to a password sign-in is refused with the same message a wrong secret gives. Create a Password Client instead. SuiteBrain AI’s setup tests for this and tells you which one it is.
Why a Password Client and not Client Credentials?
A client credentials token carries no user, so SuiteCRM has nobody to apply roles to. With a Password Client each person signs in as themselves and their own SuiteCRM permissions decide what the assistant can see and change.
Does anything get installed on the SuiteCRM server?
No module and no code. An administrator creates one OAuth2 client in the Admin screens. The OAuth2 key pair is part of the V8 API itself; if tokens are never issued, it is usually missing.
Our SuiteCRM is on a private network. Can it connect?
The hosted service has to reach your SuiteCRM over the internet, and it refuses private network addresses. For a CRM that stays inside your network, the Business plan includes a self-hosted licence and Enterprise runs air-gapped.

Next: connect it in 60 seconds, read what we store and what we never do, or book a demo and we will check your instance with you.

Say it.
Done.

Every CRM your team already has, now something they will use.