Authentication
Create, store, revoke, and rotate API keys for server-side integrations.
Create a key under Developers > API keys > Create API key. Each key belongs to the workspace in which it was created and can call the public OTP and COD confirmation routes.
Send the key with every request
Authorization: Bearer wtf_xxxxxxxxxxxx_REPLACE_WITH_YOUR_SECRETKeys have the format wtf_<publicId>_<secret>:
| Part | Format |
|---|---|
| Prefix | wtf_ |
| Public ID | 12 lowercase base32 characters: a-z and 2-7 |
| Secret | 43 base64url characters, generated from 32 random bytes |
Send the complete key, including the prefix and public ID. Keys have no scopes, automatic expiry, or live/test modes in v1. Dashboard management uses your signed-in account; an API key does not grant dashboard access.
Store the key securely
The full key is shown once. Select Copy API key and save it in your server's secret manager or protected environment configuration.
- Keep keys server-side. Never put them in browser code, mobile apps, or public repositories.
- Avoid logging the
Authorizationheader or including keys in URLs. - Use a separate named key for each backend integration so you can revoke it independently.
- If you lose a key, create a replacement. You cannot reveal the old key again.
A workspace can have at most 10 active keys. Revoked keys do not count toward this limit. Creating another active key returns 409 API_KEY_LIMIT_REACHED when the limit is reached.
Handle authentication failures
Missing or malformed authorization, an unknown key, a wrong secret, and a revoked key all return 401 API_KEY_INVALID. The response does not distinguish these cases. See the Problem Details format.
Check that the complete key is configured and the header contains Bearer, a space, and the key. If the key was revoked, replace it; retrying the same key will not restore access.
Authenticated calls share a 20 requests per second per-key limit, across OTP and COD routes, including status reads.
Revoke or rotate a key
To revoke a key, open Developers > API keys, select Revoke, then confirm with Revoke API key. Revocation is immediate and permanent.
For routine rotation:
- Create and securely save a new key in the same workspace.
- Update your backend configuration and deploy it.
- Confirm requests succeed with the new key.
- Revoke the old key.
Keep an active-key slot available for rotation. If a key is exposed, revoke it promptly and replace it. A replacement key in the same workspace can read existing messages and confirmations; idempotency is scoped to the workspace, not to the key.