Skip to main content
POST
Create Customer Key

Authorizations

Authorization
string
header
required

Your API key (ta_live_…) from Settings → API keys, sent as Authorization: Bearer <key>. Keep it on a server: it can message every customer you have. A key is full, build or read-only; a request its level does not allow is refused with 403.

Path Parameters

id
string
required

The customer's id (org_…), as Create Customer answered.

Body

application/json
name
string
required

What the key is for, so you know what to revoke later. Trimmed.

Required string length: 2 - 80
Example:

"Sunrise front-desk dashboard"

scope
enum<string>
default:full

The key's access level: full, build (everything except messaging customers, sending codes and placing calls) or read.

Available options:
full,
build,
read
Example:

"read"

Response

The key, with its secret shown this once.

A new key, with its secret.

id
string<uuid>
required

The key's id, for revoking it.

Example:

"0c7e4a92-3d1b-4f6a-8e25-91b7c3d4f5a6"

name
string
required

What you called it.

Example:

"Sunrise front-desk dashboard"

prefix
string
required

The key's first characters, so you can tell keys apart.

Example:

"ta_live_Xk3pQ9"

scope
enum<string>
required

Its access level: full everything; build everything except messaging customers, sending codes and placing calls; read reads only.

Available options:
full,
build,
read
Example:

"read"

createdAt
string<date-time>
required
Example:

"2026-10-03T08:22:10.511Z"

lastUsedAt
string<date-time> | null
required

When it last made a request; null if never.

Example:

"2026-10-06T09:58:47.090Z"

revokedAt
string<date-time> | null
required

When it was revoked; null while it works.

Example:

null

key
string
required

The key itself, to send as Authorization: Bearer <key>. Shown in this response only.

Example:

"ta_live_Xk3pQ9vLr2mT7yHc4bN8sJd1Wq6Ez0aUo5iKf3gPxRt"