Skip to Content
Coming soon · Public API preview. Access is not open yet and the API may change. Join the waitlist.
The Thumela documentation
Authentication

Authentication

The send and message-status endpoints require a bearer API key. Keys are currently provisioned for internal access; there is no public key-creation dashboard.

Authorization: Bearer th_live_<your-key>

The value above is a placeholder. Keys belong to an organisation. Sending domains and suppression entries are checked in that organisation’s context, and status lookups cannot read another organisation’s messages.

Keep keys on the server

Store the key in your server’s secret configuration. Read it through a server-only environment variable. Do not include keys in URLs, screenshots, logs, committed files, frontend bundles or variables prefixed with PUBLIC_ or NEXT_PUBLIC_.

Invalid and revoked keys

Missing, malformed, unknown and revoked keys return the same 401 Unauthorized response:

{ "statusCode": 401, "name": "Unauthorized", "message": "Invalid or missing credentials." }

Check the configured key and its access status. Repeating the same request with the same invalid key will not resolve the error.