Skip to main content
A YCloud API key is an account-level credential used to authenticate requests to YCloud APIs. Send it in the X-API-Key request header from trusted server-side systems. The account API key can call all APIs available to your YCloud account. It is not limited to an individual user, team, or WhatsApp Business phone number, so treat it as a highly sensitive secret.
Never expose an API key in browser or mobile application code, source control, logs, screenshots, tickets, or chat messages. Store it in a secret manager and grant access only to systems and people that need it.

Who can view the API key

Only account members whose assigned role grants access to Developers > API key can open the page and reveal the key. Review account roles and permissions in Users and Teams. Revealing an API key requires two-factor authentication (2FA). Each authorized user must configure 2FA for their own YCloud login before they can view the key. To configure or update 2FA, open Security settings.

View the API key

  1. Sign in to the YCloud dashboard.
  2. Go to Developers > API key.
  3. Find the key that you want to use.
  4. Click the eye icon in the API key column.
  5. Complete the 2FA verification when prompted.
  6. Copy the key and store it in your secret manager.
The key is masked by default. YCloud requires 2FA whenever an authorized user needs to reveal it.
API key page with the default key masked and the eye icon indicated.

The key remains masked. Use the eye icon only when you are ready to complete verification and store the key securely.

Rotate a compromised API key

YCloud supports one account-level API key for standard integrations. If you believe the key has been exposed, create a replacement key and rotate your systems carefully.
Creating a replacement key does not automatically delete or disable the previous key. The old key remains usable until you delete it manually.
  1. Go to Developers > API key.
  2. Click Add API Key to generate a replacement.
  3. Store the new key securely.
  4. Replace the old key in every service, environment, and secret store used by your organization.
  5. Test the affected integrations with the new key.
  6. After confirming that all systems use the new key, manually delete the old key.
Do not delete the old key before your systems have switched to the replacement, or API requests that still use it will fail.

Use multiple keys with custom apps

If your organization needs separate keys for multiple integrations, use custom apps. Each custom app has its own API key and lets you control its API permissions, WhatsApp assets, and webhook configuration. This is the recommended approach when integrations need separate credentials or different access scopes.