Skip to main content
Docs menu: Authentication

Get started

Authentication

Every request to the Telvana API carries a workspace API key in the x-api-key header.

Send your API key in the x-api-key header on every request:

curl "https://api.telvana.com/tags" \
  -H "x-api-key: $TELVANA_API_KEY"

The API is served over HTTPS only, at https://api.telvana.com.

Keys belong to a workspace

A key works on the workspace it was created in: that workspace's agents, phone numbers, conversations and knowledge bases. It can't read or change anything in another workspace. If your organization runs several workspaces, create a key in each one you connect to.

Create a key

  1. Sign in at app.telvana.com.
  2. Open Settings, then API Keys.
  3. Choose Create API Key and give it a name that says where it runs, such as "CRM sync" or "Staging".
  4. Copy the key from the dialog.

That dialog is the only time the key is shown. Telvana keeps a hash of it rather than the key itself, so a lost key can't be recovered. Create a new one instead.

Use a separate key for each system or environment, so the names on the API Keys page show which integration each key belongs to.

Keep keys on your server

Anyone who has a key can act on your workspace through the API, so:

  • Call the API from your backend. Never put a key in a web page, a mobile app or anything else that runs on someone else's device.
  • Keep keys in a secrets manager or environment variables, out of source control and logs.
  • If a key may have been exposed, email support@telvana.com so we can revoke it, and switch your integration to a new key.

When authentication fails

A request with a missing or unknown key gets a 401:

{
  "error": {
    "message": "Unauthorized",
    "statusCode": 401
  }
}

Check that the header is named x-api-key, that the key was copied whole, and that it belongs to the workspace you mean to reach. Other failures are described in Errors.