<!-- https://missblue.dev/help/articles/create-and-rotate-api-keys -->

[API & integrations](https://missblue.dev/help/collections/api-and-integrations)

# Create, rotate, and revoke an API key

Choose live or sandbox mode, show or copy a key again when you need it, and replace a credential without losing track of its use.

Miss Blue team  Updated September 30, 2026  2 min read

[Browse this collection](https://missblue.dev/help/collections/api-and-integrations)

## Create a key in the correct project

You can show or copy the key again later from the API keys list, if you are an admin or made the key. A project key can act on that project’s numbers, so create it in the same project as the intended sending line.

1.  Open API keys from the intended project and choose Create key.
2.  Give it a recognizable name, such as Appointment integration, so you can identify the system using it later.
3.  Choose Live — real messages or Sandbox — simulated responses.
4.  Create the key and copy it into your server or integration’s secret storage.

## Check the credential’s mode

Use Authorization: Bearer with the key on your server. Do not embed it in a website button, a downloadable file, browser JavaScript, or a URL. Webhook signing secrets are different credentials.

-   mb\_live\_ selects live traffic from accessible project numbers.
-   mb\_sandbox\_ selects isolated simulation and does not need a paid number.
-   Legacy mb\_test\_ credentials can still reach live traffic. The word test is not a guarantee of simulation.

## Replace a key deliberately

If a credential has been exposed, revoke it promptly and investigate its use. A lost key can be shown again from API keys by an admin or by whoever made it. A key made before September 30, 2026 was kept only as a hash, so replace it instead. Revocation does not delete conversation history.

1.  Create a replacement key in the same project and mode.
2.  Update the integration’s secret configuration and verify that it can read the intended resources. Use the sandbox for simulated sends.
3.  Confirm every system using the old key has been updated.
4.  Revoke the old key from API keys and verify the intended integration still works.

-   [API authentication and getting started](https://missblue.dev/docs)

## Related articles

-   [Test your integration in the sandbox Simulate sends, replies, and failures before connecting your integration to a real number. 2 min read](https://missblue.dev/help/articles/test-with-the-sandbox)
-   [Set up webhooks for replies and delivery events Choose events, store the signing secret, and diagnose a receiver that is not accepting deliveries. 3 min read](https://missblue.dev/help/articles/set-up-webhooks)
-   [Prevent duplicate messages from retries and automations Trace repeated sends and make a retry decision without messaging the customer twice. 2 min read](https://missblue.dev/help/articles/prevent-duplicate-messages)

## Still need a hand?

Send us your question, or text the team at (929) 272-7048.

[Contact the team](https://missblue.dev/contact)  [Text us](sms:+19292727048)
