Docs

Guides

Auth, scopes, and tenant access

API keys remain the server-to-server path. OAuth is for installable apps after review.

API keys

Keys use the cf_ prefix. Send X-API-Key or Authorization: Bearer. Every call needs X-Tenant-Id. The key must be allowlisted for that tenant. Partner allowAllTenants keys are operator credentials, not ordinary customer keys.

User attribution

Operations that act as a person require X-User-Email. The user must belong to the same tenant. SMS list and send are limited to conversations assigned to that user.

OAuth

Approved integration apps can use client credentials for a tenant install, or authorization code with PKCE. Access tokens use the cfa_ prefix and map to the same permission keys as API keys. User session JWTs are not OAuth tokens.

Sandbox

Sandbox keys only work on a sandbox tenant. They cannot originate on the PBX or send carrier SMS.