Skip to main content
If you run several Tuco workspaces under one agency account, an agency API key lets you manage the whole group from one credential: create a workspace for a new client, move a line between clients, and pull numbers across every workspace — without signing in and without juggling one key per workspace.
Agency API keys are only available on agency accounts. If you have a single workspace, use a normal workspace API key — it already does everything you need.

The two kinds of key

Tuco has two API keys and they are not interchangeable. You can tell them apart by the prefix. A workspace key sent to an agency endpoint is refused with AGENCY_KEY_REQUIRED, and an agency key sent anywhere else is refused with AGENCY_KEY_WRONG_ENDPOINT. Neither is a silent failure — the error tells you which key to use.

Creating an agency key

  1. Open the agency view (the workspace switcher → Agency view).
  2. Go to Settings → API key.
  3. Give the key a name and press Create agency key.
  4. Copy the key. It is shown once and never again.
Only the agency owner sees this screen. Agency co-admins can use the agency dashboard but cannot create, list or revoke agency keys. Revoking is immediate: press Revoke and the key stops working on the next request.

What an agency key can do

That is the whole list. An agency key cannot send a message, upload a lead, read a conversation, manage your card or create another API key. For any of that, use the workspace key for the workspace you mean.

What an agency key deliberately cannot do

  • Leave your group. Every workspace id you pass is checked against your agency. Another agency’s workspace is refused, and another agency’s key cannot touch yours.
  • Delete anything. Deleting a line is reversible only by re-provisioning it, so it stays on a signed-in agency-owner session. An agency key moving a line is safe: one more call moves it back.
  • Create or revoke API keys. Key management is session-only, so a leaked key cannot be used to issue more keys.
  • Touch your card or your members. /api/agency/billing, /api/agency/members and /api/agency/admins stay in the dashboard. The key can subscribe a client to a plan on the card, but cannot change the card.
  • Reach outside your own agency. Lines move between YOUR workspaces. Moving one to a different agency is not something either side can do — that still comes to us.

Authentication

Send the key as a bearer token, exactly like a workspace key:
Unlike workspace keys, agency keys are not accepted via HTTP Basic auth — a group-wide credential travels in the Authorization header only.

Two ways your agency pays

Both modes still put every client on a plan — that’s what grants its line limits, not the charge. Invoice billing is arranged with Tuco; it is not self-serve.

Errors

A AGENCY_KEY_WRONG_ENDPOINT response tells you what to do next:

A typical onboarding script

Create the client’s workspace, then mint a workspace key inside it from the dashboard to do the day-to-day sending.