Skip to main content
An API key lets your own code do what you can do in the dashboard — create assistants, read calls, start campaigns.

Creating one

Open API Keys and create one. Give it a name that says where it’ll be used, so you can tell them apart later.
The key is shown once, when you create it. Copy it then. We only store a hash, so if you lose it, nobody can recover it — you create a new one and delete the old.
Use it as a bearer token:
See the API overview for what you can do with it.

Looking after them

One key per thing that uses it. Separate keys for your production integration and your test script means you can revoke one without breaking the other. Keep them out of your repository. Use environment variables or your platform’s secret storage. Disable rather than delete while you’re working out whether a key is still in use. Disabling is reversible; deleting isn’t.

Scope

A key acts as the person who created it, in the organisation they were in at the time. It can reach everything that person can. If someone leaves, review the keys they made.