Skip to content

Get started

API keys: create, store and revoke

Workspace owners and admins create API keys in the app. Each key belongs to one workspace, has a read or write scope, is shown only once and expires after 365 days.

How do I create a key?

  1. Open API keys in the app

    Sign in as an owner or admin of the workspace and open API keys.

  2. Name it and pick a scope

    Use a name that says where the key is used (2–80 characters), and pick read for read-only integrations or write to send messages and change data.

  3. Copy the key

    The full key (pk_live_ + 48 hex characters) is shown once. whatsappx.si stores only a SHA-256 hash, so a lost key cannot be recovered; create a new one instead.

What does a key look like after creation?

Lists show the key’s metadata, never the secret:

FieldMeaning
idKey id, used to revoke it.
nameThe name you chose.
prefixThe first 16 characters (for example pk_live_3f9a1c0b), to recognise the key.
scoperead or write.
created_at, expires_atUnix seconds. expires_at is 365 days after creation.
revoked1 after the key was revoked, otherwise 0.
keyThe secret, only in the create response.

How do I rotate a key?

Keys cannot be renewed or rotated in place. Before expires_at:

  1. Create a new key with the same scope.
  2. Deploy it to your integration.
  3. Revoke the old key. Requests with it then fail with 401 and invalid or expired API key.

How should I store keys?

  • Keep keys on your server, in a secret manager or environment variable. Never ship them in browser or mobile code.
  • Use one key per integration, so you can revoke one without breaking the others.
  • Prefer read keys for anything that only reads.

Can I manage keys through the API?

The key endpoints exist, but they are Console only: they work with a signed-in owner or admin session, and API keys get 403 with API keys cannot administer workspaces.

Key endpoints