X-API-Key request header from trusted server-side systems.
The account API key can call all APIs available to your YCloud account. It is not limited to an individual user, team, or WhatsApp Business phone number, so treat it as a highly sensitive secret.
Who can view the API key
Only account members whose assigned role grants access to Developers > API key can open the page and reveal the key. Review account roles and permissions in Users and Teams. Revealing an API key requires two-factor authentication (2FA). Each authorized user must configure 2FA for their own YCloud login before they can view the key. To configure or update 2FA, open Security settings.View the API key
- Sign in to the YCloud dashboard.
- Go to Developers > API key.
- Find the key that you want to use.
- Click the eye icon in the API key column.
- Complete the 2FA verification when prompted.
- Copy the key and store it in your secret manager.
The key is masked by default. YCloud requires 2FA whenever an authorized user needs to reveal it.
The key remains masked. Use the eye icon only when you are ready to complete verification and store the key securely.
Rotate a compromised API key
YCloud supports one account-level API key for standard integrations. If you believe the key has been exposed, create a replacement key and rotate your systems carefully.- Go to Developers > API key.
- Click Add API Key to generate a replacement.
- Store the new key securely.
- Replace the old key in every service, environment, and secret store used by your organization.
- Test the affected integrations with the new key.
- After confirming that all systems use the new key, manually delete the old key.

