Choose a language

My API key has leaked. What should I do?

Revoke or rotate it at once, check its request log and create a new, restricted key.

Act at once: revoke the key in Account > Developers, or rotate it with a grace period of 0 hours. Revoking is immediate and needs no password. Then check the key's request log and your Wallet for activity you do not recognise, and create a new key with an IP allowlist and a daily spend cap. Keep keys only on servers, never in apps or web pages. See API keys and security.

Was this article helpful?

Still need help?

Write to us. We answer every message, usually within a few hours.

Or email us at support@smsgrab.com