Genuka WA docs

Authentication

API keys, scope, and rotation practices.

Every request authenticates with an API key in the Authorization header:

Authorization: Bearer pk_live_...

You never handle a Meta token. Genuka WA holds the Cloud API credentials and rotates them for you: one Genuka API key is enough, and it only reaches your own data.

Two key scopes

ScopeAccessUse case
PartnerEvery client of the partnerA platform managing numbers for several businesses
ClientA single businessA business integrating only its own numbers

A client key reaching for another business gets 403 out_of_scope. Some endpoints — billing, plan usage — require a partner key and answer 403 partner_key_required otherwise.

Creating and revoking a key

Keys are managed from the portal, under Developers. A key is shown once at creation: Genuka stores only a fingerprint and cannot show it to you again.

To rotate without downtime: create the new key, deploy it, confirm traffic in the logs, then revoke the old one.

Error responses

StatusCodeMeaning
401missing_bearer_tokenNo Authorization header
401invalid_tokenUnknown or revoked key
403out_of_scopeThe key is restricted to another business
403partner_key_requiredEndpoint reserved for partner keys

Security

  • An API key is a server-side secret. Never ship it in a frontend or a mobile app — anyone could send messages in your name, at your expense.
  • Use distinct keys per environment and per integration: revoking then becomes surgical rather than global.
  • Every request is logged and visible in the portal.

On this page