How do I create or rotate my OneText API key?

Last updated: October 2, 2026

API keys let your custom webhooks and other tools connect securely to your OneText account. You can create a new key any time from your dashboard, choosing exactly which permissions it has. Rotating a key means creating a new one, switching your tools over to it, and then deleting the old one. Because OneText lets you have multiple active keys at once, you can rotate without any downtime

What is an API key used for?

API keys let other tools and systems connect to your OneText account, most commonly for setting up custom webhooks. Each key has its own set of permissions, so it can only access what you allow.

When should I rotate my key?

  • You think your key may have been shared, leaked, or saved somewhere public, like a code repository

  • Someone who had access to the key has left your team, or you've stopped working with an agency or developer

  • As part of a regular security routine

How many API keys can I have?

There's no limit. Many teams create a separate key for each integration, which makes it easier to rotate or delete one key without affecting the others.

Who can create or delete API keys?

Anyone with access to your OneText dashboard can create and delete API keys. We recommend regularly reviewing who has dashboard access, especially after team changes.

Rotating your key

A few minutes, with no downtime if you follow the steps in order.

Before you start

Make a list of everywhere your current key is being used, such as custom webhooks or tools your developer has built. You'll need to update each one with the new key before deleting the old key.

How do I create/rotate my key?

  1. In your OneText dashboard, go to Settings → API Credentials.

  2. Click Add new API key.

  3. Select the permissions this key needs (see Choosing permissions below).

  4. Copy your new key right away and store it somewhere secure. For security, the key is only shown once. If you lose it, you'll need to create a new one.

  5. Replace the old key with the new one in every tool or system on your list.

  6. Test that your integrations are still working as expected.

  7. Return to Settings → API Credentials and delete the old key.

Will rotating my key break anything?

Not if you follow the steps above. Your old and new keys can both be active at the same time, so your integrations keep working while you switch them over. Anything still using the old key will stop working once you delete it, so make sure everything has been updated first.

Choosing permissions

Only select the permissions your integration actually needs. This limits what the key can access if it's ever exposed.

Performance and reporting

  • View performance stats across flows, popups, campaigns, and experiments

  • View report types and generate reports

Flows and automations

  • Start and manage automated flows

  • View automations

  • View flow definitions, templates, and flow-level stats

Campaigns

  • View campaigns and their send groups

Customers and segments

  • View customer records, addresses, and payment instruments

  • View customer segments and estimate their size

Account and billing

  • View account profile, settings, and configuration

  • View invoices and pricing plans

Integrations

  • Report orders from an external commerce platform

  • Receive Omnisend consent webhooks

  • Receive Sendlane consent webhooks

Still have questions?

Contact OneText Support and we'll be happy to help.