Authentication
The send and message-status endpoints require a bearer API key. Keys are currently provisioned for internal access; there is no public key-creation dashboard.
Authorization: Bearer th_live_<your-key>The value above is a placeholder. Keys belong to an organisation. Sending domains and suppression entries are checked in that organisation’s context, and status lookups cannot read another organisation’s messages.
Keep keys on the server
Store the key in your server’s secret configuration. Read it through a server-only environment variable. Do not include keys in URLs, screenshots, logs, committed files, frontend bundles or variables prefixed with PUBLIC_ or NEXT_PUBLIC_.
Invalid and revoked keys
Missing, malformed, unknown and revoked keys return the same 401 Unauthorized response:
{
"statusCode": 401,
"name": "Unauthorized",
"message": "Invalid or missing credentials."
}Check the configured key and its access status. Repeating the same request with the same invalid key will not resolve the error.

