API reference
Blue bubbles, from your own code.
One key, one project, and a small API that sends iMessage, reads the replies, and tells you what happened. Use the guides for account setup and calling, or the reference for supported integration endpoints.
One key, one project
A key acts on its project's numbers and reads its messages. It sees nothing belonging to any other project, including others in the same workspace — the separation an agency's clients depend on.
No user behind it
Deliberate: an integration should keep working after the person who set it up leaves. Revocation takes effect on the next request; nothing is cached.
600 requests a minute
Over it you get 429 with a Retry-After in seconds. Sending is paced separately per number so a burst does not look like spam to Apple.
Authenticating
A bearer token on every request. Make one in the console under your project’s API keys. If you lose it, an admin, or whoever made it, can show it again there.
curl https://api.missblue.dev/v1/numbers \
-H "Authorization: Bearer mb_live_..."No key, an unknown key, or a revoked one all return 401. Anything belonging to another project returns 404 rather than 403, because confirming it exists would itself be the disclosure.
Use an mb_sandbox_ key for isolated simulated responses and signed test webhooks. No paid number is needed. Read the sandbox guide. Legacy mb_test_ keys still reach real traffic. Regular phone calling and account billing require a signed-in person.