Create a key in the correct project
You can show or copy the key again later from the API keys list, if you are an admin or made the key. A project key can act on that project’s numbers, so create it in the same project as the intended sending line.
- Open API keys from the intended project and choose Create key.
- Give it a recognizable name, such as Appointment integration, so you can identify the system using it later.
- Choose Live — real messages or Sandbox — simulated responses.
- Create the key and copy it into your server or integration’s secret storage.
Check the credential’s mode
Use Authorization: Bearer with the key on your server. Do not embed it in a website button, a downloadable file, browser JavaScript, or a URL. Webhook signing secrets are different credentials.
- mb_live_ selects live traffic from accessible project numbers.
- mb_sandbox_ selects isolated simulation and does not need a paid number.
- Legacy mb_test_ credentials can still reach live traffic. The word test is not a guarantee of simulation.
Replace a key deliberately
If a credential has been exposed, revoke it promptly and investigate its use. A lost key can be shown again from API keys by an admin or by whoever made it. A key made before September 30, 2026 was kept only as a hash, so replace it instead. Revocation does not delete conversation history.
- Create a replacement key in the same project and mode.
- Update the integration’s secret configuration and verify that it can read the intended resources. Use the sandbox for simulated sends.
- Confirm every system using the old key has been updated.
- Revoke the old key from API keys and verify the intended integration still works.