API Keys
Create, list, rotate, and revoke the sk_live_ secret keys your server-side integrations use to call the ThunderPhone REST API on behalf of your organization.
API keys (sk_live_...) are the primary credential for the
ThunderPhone REST API. They are secret — treat them like a
password. Each key is bound to exactly one organization; when an API
call authenticates with a key, we look up the bound org automatically,
which is why the rest of this reference never asks for an org id in
the URL path.
This page documents the endpoints for creating, listing, and revoking keys — the same operations the dashboard exposes at Settings → Keys. You can create your first key from the dashboard without ever using this API.
Endpoints
| Method | Path | Required role | Description |
|---|---|---|---|
GET | /v1/developer/api-keys | admin+ | List API keys |
POST | /v1/developer/api-keys | admin+ | Create a new API key |
DELETE | /v1/developer/api-keys/{key_id} | admin+ | Revoke an API key |
API key object
{
"id": "b1c2d3e4-...",
"name": "production",
"key_prefix": "sk_live_abcde12",
"is_active": true,
"created_at": "2026-04-20T18:24:10.113Z",
"last_used_at": "2026-04-20T18:25:06.201Z",
"revoked_at": null
}| Field | Type | Description |
|---|---|---|
id | UUID | Public id used by the revoke endpoint |
name | string | Display label |
key_prefix | string | First 15 chars of the raw key for UI display (always sk_live_ + 7 hex chars). The full key is NOT returned after creation |
is_active | boolean | false once the key is revoked |
created_at | timestamp | |
last_used_at | timestamp | null | Updated best-effort on every successful request |
revoked_at | timestamp | null | If set, the key is revoked and will no longer authenticate |
List API keys
curl https://api.thunderphone.com/v1/developer/api-keys \
-H "Authorization: Bearer sk_live_YOUR_API_KEY"Returns an array of API key objects — both active
and revoked keys, sorted by created_at descending.
Create an API key
curl -X POST https://api.thunderphone.com/v1/developer/api-keys \
-H "Authorization: Bearer sk_live_YOUR_API_KEY" \
-H "Content-Type: application/json" \
-d '{"name": "production"}'result = requests.post(
"https://api.thunderphone.com/v1/developer/api-keys",
headers={"Authorization": "Bearer sk_live_YOUR_API_KEY"},
json={"name": "production"},
).json()
new_key = result["key"]| Field | Type | Required | Description |
|---|---|---|---|
name | string | no | Display label, 1–120 chars. Defaults to "Default key" |
Returns 201 Created with the API key object plus
an extra top-level key field containing the raw sk_live_ value:
{
"id": "b1c2d3e4-...",
"name": "production",
"key_prefix": "sk_live_abcde12",
"is_active": true,
"created_at": "2026-04-20T18:24:10.113Z",
"last_used_at": null,
"revoked_at": null,
"key": "sk_live_abcdef1234567890abcdef1234567890abcdef123456"
}Revoke an API key
curl -X DELETE https://api.thunderphone.com/v1/developer/api-keys/b1c2d3e4-... \
-H "Authorization: Bearer sk_live_YOUR_API_KEY"Returns 204 No Content. Revoked keys are permanently invalidated —
all future requests using the key return 401 Unauthorized. You
cannot un-revoke; create a new key instead.