Skip to content

API keys and scopes

Your tests call the API with an API key. A key belongs to one workspace: every inbox, message and pattern it reaches is that workspace’s, and the flat /v1 routes need no workspace in the path. Send it as a bearer token:

Authorization: Bearer wx_...

Keys are created and revoked on the workspace’s API keys page in the dashboard, by a workspace Admin. A key starts with wx_ and is shown once, when it is created: Waridex stores only a hash of it, so copy it into your CI secrets straight away. A revoked key is refused from its next request with 401 auth.unauthorized. A workspace holds at most 20 active keys.

The dashboard's Create API key dialog: a name, the Test runner preset chosen among Read only, Full access and Custom, and the scopes as checkboxes grouped into Email, Inboxes, SMS and Workspace, with email, inbox and inbox ticked and the reserved scopes muted.

A key holds exactly the scopes listed on it, at least one; no scope includes another. A new key starts with the three a test run needs: email:read, inbox:create and inbox:delete.

ScopeAllows
email:readlist inboxes and tags; list, search, read and download messages; wait; read patterns, the workspace and its statistics
email:deletedelete messages
email:injectinject a message into an inbox of the workspace
inbox:createcreate inboxes
inbox:deletedelete inboxes, and delete every inbox of a tag
pattern:manageadd and delete pinned patterns
authenticator:usethe whole authenticator channel: add, list, read and delete authenticators, purge them by tag, and read their codes and the code log

Two more scopes exist for people rather than keys and can never be put on one: keys:manage, which manages the workspace’s API keys, and workspace:admin, which renames the workspace and covers everything else under it. A workspace Admin holds both.

A few scopes can also be put on a key reserved for features that are not available yet — email:reply, webhooks:manage and the sms: scopes — so a key made now needs no change when those features arrive. They allow nothing today, and the dashboard marks them as reserved.

A call without the scope it needs is refused with 403 scope.missing, and the problem’s requiredScope names the scope. People signed in to the dashboard are held to the same scopes through their workspace role.

Each key may make 60 wait calls and 600 other calls a minute. Adding an authenticator and asking it for a code count against the wait allowance, not the other one, since they too may hold. Beyond either, the API answers 429 rate_limit.exceeded with a Retry-After header giving the seconds to wait. Test suites that run many workers in parallel can give each pipeline its own key.