X-API-Key header. Each key has a fixed scope chosen at creation time. The plaintext value is returned only once when the key is created — store it securely; it cannot be retrieved again.
Scopes
Every API key has one of two scopes. Scope is fixed at creation and cannot be changed later.Admin-scoped
Org-wide authority. An admin-scoped key can act on any resource in the organization and manage org-level configuration — including custom email domains, 10DLC compliance, contact rules, and note access grants.Agent-scoped
Bound to a single agent identity. The key can only operate as — or on resources owned by — that one agent. Agent-scoped keys are typically issued during the agent signup flow.What each scope can do
Endpoints that require an admin-scoped key return
403 when called with an agent-scoped key.
Minting rules
Who can mint which kind of key:
When minting from an admin-scoped API key, pass
scoped_identity_id in the request body to bind the new key to a specific agent identity.
Scope is fixed at creation. To rotate a key, mint a new one and revoke the old one.
Agent-scoped keys can also be obtained programmatically via the agent signup flow, which mints a key bound to the newly-claimed identity.
Create an agent-scoped key
scoped_identity_id. You can retrieve the UUID from the identity API.
cURL
Response (201)
An agent-scoped caller receives
403. An admin-scoped caller that omits scoped_identity_id also receives 403. An identity outside your organization or an unknown UUID returns 404.
To create an admin-scoped key, use the Inkbox Console.
Inspect a key
Response (200)
JSON
scoped_identity_id is null for admin-scoped keys, or an identity ID for agent-scoped keys.
Code examples
Update a key
Updating a key’s label or description is supported from the console. Scope, status, and other fields are immutable from any caller.Revoke a key
401 Unauthorized.
Response (200)
JSON
Code examples
Choosing a scope
- Use agent-scoped keys for per-agent runtime credentials. Each agent gets its own key, narrowed to that identity.
- Use admin-scoped keys for backend orchestration: provisioning agents, configuring custom domains and 10DLC, and managing contact rules and access grants.
- Don’t ship admin-scoped keys to end-user agents. Mint an agent-scoped key per agent instead.
Related
- Agent signup — claim an agent identity and receive its initial API key
- Identities — agent identity model
- Signing keys — verify the authenticity of webhooks Inkbox sends to you
- Webhooks — receive events from Inkbox

