Authentication
API keys, the X-API-Key header and scopes.
Every request is authenticated with an API key sent in the X-API-Key header.
curl https://api.resonera.ai/agents \
-H "X-API-Key: rsn_live_your_key_here"Creating a key
In the dashboard, open Settings → API access and choose New key. Pick the scopes the integration needs and, optionally, a daily dispatch cap. The key is shown once. Resonera stores only a one-way hash, so a lost key can't be recovered: revoke it and create a new one.
Keys start with rsn_live_, so a leaked key is easy to spot in logs or a code search.
A key acts on your account within its scopes, including placing calls that use your balance. Keep it on a server. Never put it in a browser, a mobile app or a public repository.
Scopes
A key can only do what its scopes allow. A request outside them returns 403.
| Scope | Allows |
|---|---|
agents:read | List agents and knowledge-base documents; read agent settings and indexing status. |
agents:write | Create, edit and delete agents; upload and delete knowledge-base documents; assign agents to phone numbers. |
calls:read | List campaigns, calls and phone numbers; read transcripts, outcomes and recordings. |
calls:write | Create, pause and delete campaigns. Places no calls. |
calls:dispatch | Launch campaigns and place test calls. Spends your balance. |
webhooks:manage | Register, change and remove webhook endpoints. |
Give each system only what it needs. A job that writes results back to your CRM needs just
calls:read. If a person should approve each batch before dialing, give the integration
calls:write without calls:dispatch and press Launch in the dashboard.
Daily dispatch cap
When creating a key you can set the most calls it may start per day (1 to 100,000). Launches and
test calls past the cap return 429 until 00:00 UTC. With no cap set, the key is limited only by
your plan and balance.
What a key can see
A key belongs to the organization it was created in and sees that organization's agents,
campaigns, calls and numbers. Anything else returns 404, the same as something that doesn't
exist.
Revoking a key
Revoke a key from Settings → API access. It stops working immediately. Its usage history is kept, so you can still see what it did.