Guides
Auth, scopes, and tenant access
API keys remain the server-to-server path. OAuth is for installable apps after review.
API keys
Keys use the cf_ prefix. Send X-API-Key or Authorization: Bearer. Every call needs X-Tenant-Id. The key must be allowlisted for that tenant. Partner allowAllTenants keys are operator credentials, not ordinary customer keys.
User attribution
Operations that act as a person require X-User-Email. The user must belong to the same tenant. SMS list and send are limited to conversations assigned to that user.
OAuth
Approved integration apps can use client credentials for a tenant install, or authorization code with PKCE. Access tokens use the cfa_ prefix and map to the same permission keys as API keys. User session JWTs are not OAuth tokens.
Sandbox
Sandbox keys only work on a sandbox tenant. They cannot originate on the PBX or send carrier SMS.