# API Keys

API keys are optional. Finish [sign-up](https://docs.voicelogica.ai/getting-started/sign-up/), [subscription](https://docs.voicelogica.ai/getting-started/activate-subscription/), and [your first agent](https://docs.voicelogica.ai/getting-started/your-first-agent/) before you need them.

They are programmatic credentials for the Voice Logica API. Each key is scoped to the operations you allow and can be limited to one IP address. The same key also signs MCP clients (ChatGPT, Claude) into your workspace.

Open **Team and access** from the Account group in the sidebar, then select the **API Keys** tab. That page also has **Members**, **Pending invitations**, and **Access Requests**.

> **Note:** Keys for AI providers (OpenAI, ElevenLabs, ...) live on the **AI Provider Keys** page, not here.
## Creating an API Key

1. **Open API Keys and start a new key**

   On the **API Keys** tab, click **+ Api Key**.

     ![API Keys tab with + Api Key button](https://docs.voicelogica.ai/assets/getting-started/api-keys-0.png)

2. **Choose a preset, name the key, and set an IP if needed**

   The **Create API key** drawer opens on the right.

   - **Preset** - start from Full access (every operation) or another preset, then refine below.
   - **API Key Name** - use a clear purpose name such as `CRM Integration`, `Webhook Handler`, or `Initiate Call`.
   - **IP Address** - optional. Leave it blank to allow any IP. Only enter a real address when the caller has a fixed IP. Do not enter `0.0.0.0` as a stand-in for "any IP"; blank already means any IP.

     ![Create API key drawer with CRM Integration name](https://docs.voicelogica.ai/assets/getting-started/api-keys-1.png)

3. **Choose the allowed operations**

   Under **API operation restrictions**, expand each group and toggle what this key may call. Groups include **Calls**, **Agents**, **Workflows**, **VoIP & SIP**, **SMS**, **MCP**, **Billing**, **Shopify**, and **Campaigns**. Leave everything on for full access, or switch off what the key does not need.

     ![API operation restriction groups](https://docs.voicelogica.ai/assets/getting-started/api-keys-2.png)

4. **Create the key and copy it once**

   Click **Create API Key**. The **Copy your API key** dialog shows the full value only this once. Click **Copy**, store the key somewhere safe, then click **Done**.

     ![Copy your API key dialog](https://docs.voicelogica.ai/assets/getting-started/api-keys-3.png)

> **The key is shown only once:** After you close that dialog, the table only shows a masked key. You cannot view the full value again. If you lose it, revoke the key and create a new one.
> **Least privilege:** Grant only the operations a key needs, use a separate key per integration, and set an IP restriction when the caller has a fixed address. If a key is exposed, revoke it immediately.
## Managing Your Keys

The table lists each key's **Name**, masked **Key**, **Last Used**, and **Created** date. Use search to find a key by name.

  ![API keys table with CRM Integration](https://docs.voicelogica.ai/assets/getting-started/api-keys-4.png)

- **Edit** (pencil) - change the name, IP restriction, and allowed operations. The secret value itself never appears again and cannot be rotated in place.
- **Revoke** (trash) - opens **Revoke API key?** Confirm with **Revoke** to permanently remove the key. Apps using it lose access immediately. There is no separate Delete action.

## Using Your API Key

Authenticate requests by sending the key in the `x-api-key` header:

```
x-api-key: YOUR_API_KEY
```

For example, starting an outbound AI call:

```bash
curl -X POST https://api.voicelogica.ai/api/v1/phones/calls/initiate-call \
  -H "x-api-key: YOUR_API_KEY" \
  -H "Content-Type: application/json" \
  -d '{
    "destinationNumber": "+302101234567",
    "agentId": "your-agent-id",
    "voipPhoneId": "your-voip-phone-id"
  }'
```

`destinationNumber` is required; pass `agentId` for outbound AI calls, and either `voipPhoneId` or `sipTrunkId` to choose the line the call goes out on. The full interactive reference for every endpoint lives at [api.voicelogica.ai/api-docs](https://api.voicelogica.ai/api-docs).

> **Note:** Outbound calls respect destination-country calling rules by default - for example no calls between 21:00-09:00 local time. The API exposes explicit override flags if your use case requires them; inbound calls are never restricted.
## Troubleshooting

**My requests return 401 Unauthorized**

- Confirm the key is sent in the `x-api-key` header - not as a `Bearer` token.
- Check the key has not been revoked from the API Keys table.
- If the key has an IP restriction, verify the request comes from that exact address.

**My requests return 403 Forbidden**

- The key's operation restrictions do not include the endpoint you are calling - edit the key and enable the relevant operation group.

## Next Steps

> **Build on the API:** Explore the [interactive API reference](https://api.voicelogica.ai/api-docs), then automate with [Workflow Triggers](https://docs.voicelogica.ai/workflows/) - or connect an MCP client like ChatGPT or Claude to your workspace using the same key.
## Need Help?

If you run into any issues, the Voice Logica support team is available:

- EMAIL [support@voicelogica.ai](mailto:support@voicelogica.ai)
- DEVELOPERS [developers@voicelogica.ai](mailto:developers@voicelogica.ai)
- API REFERENCE [api.voicelogica.ai/api-docs](https://api.voicelogica.ai/api-docs)
