API keys

Create, list and delete API keys programmatically.

Manage the workspace's API keys with a full_access key. Permissions are explained in Authentication.

Create an API key

POST/api/v1/api-keys

Body

namestringrequired
A name to recognise the key by (1–200 characters).
permission"full_access" | "sending_access"default full_access
sending_access keys can only send emails. Defaults to sending_access when domain_id is set.
domain_idstring
Restrict a sending_access key to one domain of the workspace. Can't be combined with full_access.
# Create a sending key
curl -X POST 'https://api.bytesms.com/api/v1/api-keys' \
  -H 'Authorization: Bearer tp_live_xxxxxxxxx' \
  -H 'Content-Type: application/json' \
  -d '{"name":"Production server","permission":"sending_access","domain_id":"cmg4jz1pb0000l8v9a6c3e2kf"}'
Response
{
  "id": "cmg4m9t2c0004l8v9r5x1k7wd",
  "token": "tp_live_3f9c1a7e5b2d4f60a8c9e1b3d5f7a9c2e4b6d8f0a1c3e5b7c9d1e3f5a7b9c1d3"
}
token is the only time the full key is returned. Store it securely. Your plan may cap the number of keys (403 plan_limit_exceeded, code: api_key_limit_reached).

List API keys

GET/api/v1/api-keys
# List API keys
curl -X GET 'https://api.bytesms.com/api/v1/api-keys' \
  -H 'Authorization: Bearer tp_live_xxxxxxxxx'
Response
{
  "object": "list",
  "has_more": false,
  "data": [
    {
      "id": "cmg4m9t2c0004l8v9r5x1k7wd",
      "name": "Production server",
      "permission": "sending_access",
      "domain_id": "cmg4jz1pb0000l8v9a6c3e2kf",
      "created_at": "2026-09-28T08:30:00.000Z",
      "last_used_at": "2026-09-28T09:12:44.000Z"
    }
  ]
}

Delete an API key

DELETE/api/v1/api-keys/{api_key_id}

Revokes the key immediately. Requests made with it afterwards get 401.

# Delete an API key
curl -X DELETE 'https://api.bytesms.com/api/v1/api-keys/cmg4m9t2c0004l8v9r5x1k7wd' \
  -H 'Authorization: Bearer tp_live_xxxxxxxxx'
Response
{
  "object": "api_key",
  "id": "cmg4m9t2c0004l8v9r5x1k7wd",
  "deleted": true
}