API keys
Create an API key
Creates a key that expires in 365 days. The response is the only time the full key is shown; whatsappx.si stores only a SHA-256 hash of it.
- Console only: owner or admin
- Workspace:
X-Tenant-ID
Headers
CookiestringrequiredThe
whatsappx_sessioncookie the app sets when you sign in. Browsers send it automatically; API keys are not accepted on this endpoint.X-Tenant-IDuuidrequiredWorkspace id. Required for session requests. You can pass
?tenant=<id>instead.
Body
application/jsonnamestringrequiredA name to recognise the key by.
scopeenumrequiredreadallows GET requests only;writeallows every request an API key may make.fullandfull_accessare accepted aswrite.
Response
201 Createdapplication/json
iduuidKey id. Use it to delete the key.
namestringName you gave the key.
prefixstringFirst 16 characters of the key (for example
pk_live_3f9a1c0b), so you can recognise it.scopeenumreadorwrite.created_atintegerCreation time in Unix seconds.
expires_atintegerExpiry time in Unix seconds (365 days after creation).
revokedinteger1once the key has been deleted (revoked), otherwise0.keystringmay be absentThe full secret key. Returned only in the create response.
Status codes
- 201Created. The new key, including the secret
key. - 400Bad request.
name must be 2–80 characters,scope must be read or write (full access)orinvalid body. - 401Unauthorized. No signed-in session (
unauthorized). - 403Forbidden. API keys can never call this endpoint (
API keys cannot administer workspaces). A signed-in user who is not an owner or admin getsadmin required; a user who is not a member of the workspace getsforbidden.