Skip to main content
API keys authenticate every request to the Inkbox API. Pass the key in the X-API-Key header. Each key has a fixed scope chosen at creation time. The plaintext value is returned only once when the key is created — store it securely; it cannot be retrieved again.

Scopes

Every API key has one of two scopes. Scope is fixed at creation and cannot be changed later.

Admin-scoped

Org-wide authority. An admin-scoped key can act on any resource in the organization and manage org-level configuration — including custom email domains, 10DLC compliance, contact rules, and note access grants.

Agent-scoped

Bound to a single agent identity. The key can only operate as — or on resources owned by — that one agent. Agent-scoped keys are typically issued during the agent signup flow.

What each scope can do

Endpoints that require an admin-scoped key return 403 when called with an agent-scoped key.

Minting rules

Who can mint which kind of key: When minting from an admin-scoped API key, pass scoped_identity_id in the request body to bind the new key to a specific agent identity. Scope is fixed at creation. To rotate a key, mint a new one and revoke the old one. Agent-scoped keys can also be obtained programmatically via the agent signup flow, which mints a key bound to the newly-claimed identity.

Create an agent-scoped key

Authenticate with an admin-scoped API key and use the target identity’s UUID as scoped_identity_id. You can retrieve the UUID from the identity API.
cURL

Response (201)

An agent-scoped caller receives 403. An admin-scoped caller that omits scoped_identity_id also receives 403. An identity outside your organization or an unknown UUID returns 404. To create an admin-scoped key, use the Inkbox Console.

Inspect a key

Returns metadata for the calling key. The plaintext value is never returned again after creation.

Response (200)

JSON
scoped_identity_id is null for admin-scoped keys, or an identity ID for agent-scoped keys.

Code examples


Update a key

Updating a key’s label or description is supported from the console. Scope, status, and other fields are immutable from any caller.

Revoke a key

Revokes the calling key. Revocation is permanent — to replace a key, mint a new one before revoking the old one. You can also revoke any key from the console. Revocation is idempotent for concurrent requests: if two requests authenticate with the same key before revocation completes, both return the same revoked record. Once revoked, the key no longer authenticates. Any later request with it, including another revoke call, returns 401 Unauthorized.

Response (200)

JSON

Code examples


Choosing a scope

  • Use agent-scoped keys for per-agent runtime credentials. Each agent gets its own key, narrowed to that identity.
  • Use admin-scoped keys for backend orchestration: provisioning agents, configuring custom domains and 10DLC, and managing contact rules and access grants.
  • Don’t ship admin-scoped keys to end-user agents. Mint an agent-scoped key per agent instead.

  • Agent signup — claim an agent identity and receive its initial API key
  • Identities — agent identity model
  • Signing keys — verify the authenticity of webhooks Inkbox sends to you
  • Webhooks — receive events from Inkbox