API Key
Create and manage the API keys that authenticate requests to this API.
Find API Keys
Returns all API keys associated with your account. Each entry includes the key ID, associated username, allowed operations, traffic type, and creation date, but the full key value is not returned for security reasons. Optionally filter the list by userId to see only keys created by or assigned to a specific user. Use this endpoint to audit which keys exist before creating new ones or revoking old ones. To inspect the key that is authenticating your request, including which operations it is scoped to, use GET /authentication/me instead. Returns 500 if an internal error occurs.
Create an API Key
Creates a new API key for your account and returns the full key value in the response. IMPORTANT: The full key value is shown only once in this response. It cannot be retrieved again through any endpoint, so you must copy and store it securely immediately after creation. The key becomes active instantly and can be used to authenticate requests by passing it in the X-API-Key header. You must scope the key by listing operations (e.g. SMS, RCS, WHATSAPP) in the operations field of the request body, so that each integration gets a least-privilege key. The operations you request must be a subset of the operations held by the key making this call: a key cannot grant privileges it does not have itself. Use GET /authentication/me to check what your current key is scoped to before choosing them. If you lose a key, the only option is to delete it with DELETE /authentication/{id} and create a new one. Keys created here are identified by their id and userId and carry no username, so the username field of the response is always null. Returns 400 if the request body is malformed or missing required fields, including an absent or empty operations list. Returns 403 if the requested operations exceed the scope of the key making the call. Returns 500 if an internal error occurs.
Describe the current API Key
Returns the metadata of the API key that authenticated this request: its ID, company, user, username, allowed operations, traffic type, and creation date. Use this to verify that a key you have stored is still valid and to check which operations it is authorized for. The key is identified from the X-API-Key header, so it is never sent in the URL — this endpoint takes no parameters. The key value itself is not part of the response and remains unavailable after creation, as documented on POST /authentication. Returns 401 if the X-API-Key header is missing, unknown, or not authorized for the AUTHENTICATION operation. Returns 500 if an internal error occurs.
Delete an API Key
Permanently revokes and deletes an API key. Revocation takes effect immediately: any subsequent API request that uses the deleted key in the X-API-Key header will receive a 401 Unauthorized response. This action cannot be undone. If you delete a key by mistake, you must create a new one with POST /authentication and update all clients that were using the old key. Before deleting, ensure no active integrations or scheduled jobs depend on this key to avoid service interruptions. Returns 204 on success with no response body. Returns 404 if no key with the given ID exists or it does not belong to your account. Returns 500 if an internal error occurs.