API Key

Authenticate every request with the x-api-key header

The API Key (also called App-Key) is the simplest way to authenticate. It is a static key that you send in the x-api-key header of every request.

API Keys are issued by Voices. Request yours from the Chat Bridge team: it comes preconfigured with the account and the channel it is enabled for, so you never send them on each request. One API Key enables one channel; request one per channel you need. The Tools endpoints accept any API Key.

Usage

curl https://connect.chatbridge.mx/v1/whatsapp/accounts \
-H "x-api-key: YOUR_API_KEY"

Keep the key on your servers only. Anyone holding it can send traffic on behalf of your account; if it is exposed, ask the Chat Bridge team to disable it and issue a new one.

API Key or OAuth 2.0

Both methods identify the same App-Key, so account, channel, webhooks and rate limit are identical whichever you use, and both sets of credentials are provided by Voices.

API KeyOAuth 2.0 client credentials
Credential issued by VoicesAPI Keyclient_id + client_secret
What you send on each requestx-api-key: <API_KEY>Authorization: Bearer <access_token>
LifetimeUntil Voices disables or rotates itAccess token: 1 hour; request a new one with POST /api/oauth/token
Rotation without downtimeNew key, switch and then disable the old onePrevious client_secret keeps working 24 h

If a request carries both headers, Authorization: Bearer takes precedence. An App-Key can be switched to OAuth 2.0 only; from then on x-api-key is rejected with 401 and errorCode 450.

Errors

ScenarioHTTPerrorCodeMessage
No x-api-key nor Authorization header401401Token de autenticación requerido
The x-api-key does not exist or is incorrect401401App-key inválida
The API Key is disabled401401App-key inactiva
The API Key only accepts OAuth 2.0401450Esta app-key ya no acepta x-api-key, usa OAuth 2.0
The API Key has no access to the requested channel403403Esta app-key no tiene acceso a este canal