IllyVoIPdevelopers

Getting started

Authentication

Account API keys for server requests. Short-lived tokens for browser calling.

Server API requests

Ordinary customer requests use the X-Api-Key header. API keys are account-owner scoped. Keep the key in a server environment or secrets manager; never include it in frontend code, URLs or a public repository.

HTTP header
X-Api-Key: YOUR_API_KEY

Key management

Use Authentication & API key in the portal’s API section. Follow the verification prompts shown for your account. Coordinate credential changes with every integration that uses the key.

Browser calling

Your backend authenticates the application user, determines their authorized SIP identity and creates a short-lived browser token. The browser exchanges that token for bootstrap data with the documented Bearer authentication scheme. Do not allow the browser to choose an arbitrary account identity.

Browser bootstrap header
Authorization: Bearer YOUR_BROWSER_TOKEN

Authentication and permission errors

A missing or invalid API key can return 401. Account access and endpoint-specific permissions can return 403. Review the specific endpoint response before deciding whether to retry.

Search API operations, parameters, SDK and webhooks.