Skip to content

API keys

Create an API key

Creates a key that expires in 365 days. The response is the only time the full key is shown; whatsappx.si stores only a SHA-256 hash of it.

POST/api/v1/keys
  • Console only: owner or admin
  • Workspace: X-Tenant-ID

Headers

  • Cookiestringrequired

    The whatsappx_session cookie the app sets when you sign in. Browsers send it automatically; API keys are not accepted on this endpoint.

    Example
    whatsappx_session=…
  • X-Tenant-IDuuidrequired

    Workspace id. Required for session requests. You can pass ?tenant=<id> instead.

    Example
    8d0f6c2e-3b1a-4c55-9a7e-2f4b6d1e9c30

Body

application/json
  • namestringrequired

    A name to recognise the key by.

    Constraints
    2–80 characters.
    Example
    CRM sync
  • scopeenumrequired

    read allows GET requests only; write allows every request an API key may make. full and full_access are accepted as write.

    Example
    write

Response

201 Createdapplication/json

  • iduuid

    Key id. Use it to delete the key.

  • namestring

    Name you gave the key.

  • prefixstring

    First 16 characters of the key (for example pk_live_3f9a1c0b), so you can recognise it.

  • scopeenum

    read or write.

  • created_atinteger

    Creation time in Unix seconds.

  • expires_atinteger

    Expiry time in Unix seconds (365 days after creation).

  • revokedinteger

    1 once the key has been deleted (revoked), otherwise 0.

  • keystringmay be absent

    The full secret key. Returned only in the create response.

Status codes

  • 201Created. The new key, including the secret key.
  • 400Bad request. name must be 2–80 characters, scope must be read or write (full access) or invalid body.
  • 401Unauthorized. No signed-in session (unauthorized).
  • 403Forbidden. API keys can never call this endpoint (API keys cannot administer workspaces). A signed-in user who is not an owner or admin gets admin required; a user who is not a member of the workspace gets forbidden.