Skip to content
API & integrations

Create, rotate, and revoke an API key

Choose live or sandbox mode, show or copy a key again when you need it, and replace a credential without losing track of its use.

Create a key in the correct project

You can show or copy the key again later from the API keys list, if you are an admin or made the key. A project key can act on that project’s numbers, so create it in the same project as the intended sending line.

  1. Open API keys from the intended project and choose Create key.
  2. Give it a recognizable name, such as Appointment integration, so you can identify the system using it later.
  3. Choose Live — real messages or Sandbox — simulated responses.
  4. Create the key and copy it into your server or integration’s secret storage.

Check the credential’s mode

Use Authorization: Bearer with the key on your server. Do not embed it in a website button, a downloadable file, browser JavaScript, or a URL. Webhook signing secrets are different credentials.

  • mb_live_ selects live traffic from accessible project numbers.
  • mb_sandbox_ selects isolated simulation and does not need a paid number.
  • Legacy mb_test_ credentials can still reach live traffic. The word test is not a guarantee of simulation.

Replace a key deliberately

If a credential has been exposed, revoke it promptly and investigate its use. A lost key can be shown again from API keys by an admin or by whoever made it. A key made before September 30, 2026 was kept only as a hash, so replace it instead. Revocation does not delete conversation history.

  1. Create a replacement key in the same project and mode.
  2. Update the integration’s secret configuration and verify that it can read the intended resources. Use the sandbox for simulated sends.
  3. Confirm every system using the old key has been updated.
  4. Revoke the old key from API keys and verify the intended integration still works.