Agency API keys are only available on agency accounts. If you have a single
workspace, use a normal workspace API key — it already
does everything you need.
The two kinds of key
Tuco has two API keys and they are not interchangeable. You can tell them apart by the prefix.
A workspace key sent to an agency endpoint is refused with
AGENCY_KEY_REQUIRED,
and an agency key sent anywhere else is refused with AGENCY_KEY_WRONG_ENDPOINT.
Neither is a silent failure — the error tells you which key to use.
Creating an agency key
- Open the agency view (the workspace switcher → Agency view).
- Go to Settings → API key.
- Give the key a name and press Create agency key.
- Copy the key. It is shown once and never again.
What an agency key can do
What an agency key deliberately cannot do
- Leave your group. Every workspace id you pass is checked against your agency. Another agency’s workspace is refused, and another agency’s key cannot touch yours.
- Delete anything. Deleting a line is reversible only by re-provisioning it, so it stays on a signed-in agency-owner session. An agency key moving a line is safe: one more call moves it back.
- Create or revoke API keys. Key management is session-only, so a leaked key cannot be used to issue more keys.
- Touch your card or your members.
/api/agency/billing,/api/agency/membersand/api/agency/adminsstay in the dashboard. The key can subscribe a client to a plan on the card, but cannot change the card. - Reach outside your own agency. Lines move between YOUR workspaces. Moving one to a different agency is not something either side can do — that still comes to us.
Authentication
Send the key as a bearer token, exactly like a workspace key:Authorization header only.
Two ways your agency pays
Both modes still put every client on a plan — that’s what grants its line
limits, not the charge. Invoice billing is arranged with Tuco; it is not
self-serve.
Errors
A
AGENCY_KEY_WRONG_ENDPOINT response tells you what to do next: