ThunderPhone 2.0 is live.Self-serve, from 2¢/min.Read the announcement

Developer

API Keys

Create, list, rotate, and revoke the sk_live_ secret keys your server-side integrations use to call the ThunderPhone REST API on behalf of your organization.

API keys (sk_live_...) are the primary credential for the ThunderPhone REST API. They are secret — treat them like a password. Each key is bound to exactly one organization; when an API call authenticates with a key, we look up the bound org automatically, which is why the rest of this reference never asks for an org id in the URL path.

This page documents the endpoints for creating, listing, and revoking keys — the same operations the dashboard exposes at Settings → Keys. You can create your first key from the dashboard without ever using this API.

Endpoints

MethodPathRequired roleDescription
GET/v1/developer/api-keysadmin+List API keys
POST/v1/developer/api-keysadmin+Create a new API key
DELETE/v1/developer/api-keys/{key_id}admin+Revoke an API key

API key object

{
  "id": "b1c2d3e4-...",
  "name": "production",
  "key_prefix": "sk_live_abcde12",
  "is_active": true,
  "created_at": "2026-04-20T18:24:10.113Z",
  "last_used_at": "2026-04-20T18:25:06.201Z",
  "revoked_at": null
}
FieldTypeDescription
idUUIDPublic id used by the revoke endpoint
namestringDisplay label
key_prefixstringFirst 15 chars of the raw key for UI display (always sk_live_ + 7 hex chars). The full key is NOT returned after creation
is_activebooleanfalse once the key is revoked
created_attimestamp
last_used_attimestamp | nullUpdated best-effort on every successful request
revoked_attimestamp | nullIf set, the key is revoked and will no longer authenticate

List API keys

cURL
curl https://api.thunderphone.com/v1/developer/api-keys \
  -H "Authorization: Bearer sk_live_YOUR_API_KEY"

Returns an array of API key objects — both active and revoked keys, sorted by created_at descending.


Create an API key

cURL
curl -X POST https://api.thunderphone.com/v1/developer/api-keys \
  -H "Authorization: Bearer sk_live_YOUR_API_KEY" \
  -H "Content-Type: application/json" \
  -d '{"name": "production"}'
Python
result = requests.post(
    "https://api.thunderphone.com/v1/developer/api-keys",
    headers={"Authorization": "Bearer sk_live_YOUR_API_KEY"},
    json={"name": "production"},
).json()
new_key = result["key"]
FieldTypeRequiredDescription
namestringnoDisplay label, 1–120 chars. Defaults to "Default key"

Returns 201 Created with the API key object plus an extra top-level key field containing the raw sk_live_ value:

{
  "id": "b1c2d3e4-...",
  "name": "production",
  "key_prefix": "sk_live_abcde12",
  "is_active": true,
  "created_at": "2026-04-20T18:24:10.113Z",
  "last_used_at": null,
  "revoked_at": null,
  "key": "sk_live_abcdef1234567890abcdef1234567890abcdef123456"
}

Revoke an API key

cURL
curl -X DELETE https://api.thunderphone.com/v1/developer/api-keys/b1c2d3e4-... \
  -H "Authorization: Bearer sk_live_YOUR_API_KEY"

Returns 204 No Content. Revoked keys are permanently invalidated — all future requests using the key return 401 Unauthorized. You cannot un-revoke; create a new key instead.