API keys
Create, list and delete API keys programmatically.
Manage the workspace's API keys with a full_access key. Permissions are explained in Authentication.
Create an API key
POST
/api/v1/api-keysBody
namestringrequired- A name to recognise the key by (1–200 characters).
permission"full_access" | "sending_access"defaultfull_accesssending_accesskeys can only send emails. Defaults tosending_accesswhendomain_idis set.domain_idstring- Restrict a
sending_accesskey to one domain of the workspace. Can't be combined withfull_access.
# Create a sending key
curl -X POST 'https://api.bytesms.com/api/v1/api-keys' \
-H 'Authorization: Bearer tp_live_xxxxxxxxx' \
-H 'Content-Type: application/json' \
-d '{"name":"Production server","permission":"sending_access","domain_id":"cmg4jz1pb0000l8v9a6c3e2kf"}'Response
{
"id": "cmg4m9t2c0004l8v9r5x1k7wd",
"token": "tp_live_3f9c1a7e5b2d4f60a8c9e1b3d5f7a9c2e4b6d8f0a1c3e5b7c9d1e3f5a7b9c1d3"
}token is the only time the full key is returned. Store it securely. Your plan may cap the number of keys (403 plan_limit_exceeded, code: api_key_limit_reached).List API keys
GET
/api/v1/api-keys# List API keys curl -X GET 'https://api.bytesms.com/api/v1/api-keys' \ -H 'Authorization: Bearer tp_live_xxxxxxxxx'
Response
{
"object": "list",
"has_more": false,
"data": [
{
"id": "cmg4m9t2c0004l8v9r5x1k7wd",
"name": "Production server",
"permission": "sending_access",
"domain_id": "cmg4jz1pb0000l8v9a6c3e2kf",
"created_at": "2026-09-28T08:30:00.000Z",
"last_used_at": "2026-09-28T09:12:44.000Z"
}
]
}Delete an API key
DELETE
/api/v1/api-keys/{api_key_id}Revokes the key immediately. Requests made with it afterwards get 401.
# Delete an API key curl -X DELETE 'https://api.bytesms.com/api/v1/api-keys/cmg4m9t2c0004l8v9r5x1k7wd' \ -H 'Authorization: Bearer tp_live_xxxxxxxxx'
Response
{
"object": "api_key",
"id": "cmg4m9t2c0004l8v9r5x1k7wd",
"deleted": true
}