> ## Documentation Index
> Fetch the complete documentation index at: https://docs.inboxapp.com/llms.txt
> Use this file to discover all available pages before exploring further.

# Authentication

> Create and use an Inboxapp API token

## Get an API token

1. Open **Settings → API** in [Inboxapp](https://inboxapp.com)
2. Select **New API token**
3. Name it and select **Create**
4. Copy the token

<Warning>
  A token gives full access to your team's conversations. Keep it out of version
  control and client-side code.
</Warning>

## Use the token

Send it in the `Authorization` header of every request:

```
Authorization: Bearer YOUR_API_TOKEN
```

The token decides the team, so no path or parameter names one. To work with several teams, use one token per team.

<CodeGroup>
  ```typescript client.ts theme={null}
  const API = "https://inboxapp.com/api/v2";

  async function api<T>(path: string, init: RequestInit = {}): Promise<T> {
    const response = await fetch(`${API}${path}`, {
      ...init,
      headers: {
        Authorization: `Bearer ${process.env.INBOX_API_TOKEN}`,
        "Content-Type": "application/json",
        ...init.headers,
      },
    });

    if (!response.ok) {
      const error = await response.json();
      throw new Error(`${error.code}: ${error.message} (${error.requestId})`);
    }

    return response.status === 204 ? (undefined as T) : response.json();
  }

  const team = await api<{ name: string }>("/team");
  console.log("Connected to", team.name);
  ```

  ```javascript client.js theme={null}
  const API = "https://inboxapp.com/api/v2";

  async function api(path, init = {}) {
    const response = await fetch(`${API}${path}`, {
      ...init,
      headers: {
        Authorization: `Bearer ${process.env.INBOX_API_TOKEN}`,
        "Content-Type": "application/json",
        ...init.headers,
      },
    });

    if (!response.ok) {
      const error = await response.json();
      throw new Error(`${error.code}: ${error.message} (${error.requestId})`);
    }

    return response.status === 204 ? undefined : response.json();
  }

  api("/team").then((team) => console.log("Connected to", team.name));
  ```

  ```bash cURL theme={null}
  curl https://inboxapp.com/api/v2/team \
    -H "Authorization: Bearer $INBOX_API_TOKEN"
  ```
</CodeGroup>

## Failures

| Response | Cause |
| - | - |
| `401 unauthorized` | The header is missing or malformed, or the token was revoked |
| `403 workspaceLocked` | The team's billing is paused or past due, or its trial ended |
| `403 planRequired` | The endpoint needs a plan or add-on the team doesn't have |

## Rotate a token

Create a new token, deploy it, then delete the old one in **Settings → API**. A deleted token stops working immediately.

## AI tools

MCP clients can sign in instead of using a token. See [MCP server](/v2/mcp-server).


This documentation is built and hosted on [Mintlify](https://mintlify.com), a developer documentation platform.