Get started
API keys: create, store and revoke
Workspace owners and admins create API keys in the app. Each key belongs to one workspace, has a read or write scope, is shown only once and expires after 365 days.
How do I create a key?
Open API keys in the app
Sign in as an owner or admin of the workspace and open API keys.
Name it and pick a scope
Use a name that says where the key is used (2–80 characters), and pick
readfor read-only integrations orwriteto send messages and change data.Copy the key
The full key (
pk_live_+ 48 hex characters) is shown once. whatsappx.si stores only a SHA-256 hash, so a lost key cannot be recovered; create a new one instead.
What does a key look like after creation?
Lists show the key’s metadata, never the secret:
| Field | Meaning |
|---|---|
id | Key id, used to revoke it. |
name | The name you chose. |
prefix | The first 16 characters (for example pk_live_3f9a1c0b), to recognise the key. |
scope | read or write. |
created_at, expires_at | Unix seconds. expires_at is 365 days after creation. |
revoked | 1 after the key was revoked, otherwise 0. |
key | The secret, only in the create response. |
How do I rotate a key?
Keys cannot be renewed or rotated in place. Before expires_at:
- Create a new key with the same scope.
- Deploy it to your integration.
- Revoke the old key. Requests with it then fail with
401andinvalid or expired API key.
How should I store keys?
- Keep keys on your server, in a secret manager or environment variable. Never ship them in browser or mobile code.
- Use one key per integration, so you can revoke one without breaking the others.
- Prefer
readkeys for anything that only reads.
Can I manage keys through the API?
The key endpoints exist, but they are Console only: they work with a signed-in owner or admin session, and API keys get 403 with API keys cannot administer workspaces.