API tokens

An API token lets your backend or agent access Umney Connect resources—the same ease-of-use model as creating a Cloudflare API token so an agent can only reach the accounts and services you allow.

Why service-scoped tokens

Each Connect service has its own permissions. A Live Chat token cannot send email; a Business Email token cannot mint chat sessions. In Developers, pick the service by name (for example Business Email). Issue the narrowest token for the job, rotate on a schedule, and revoke from Dashboard → Developers.

Create a token

  1. Confirm the product is enabled under Dashboard → Billing.
  2. Open Dashboard → Developers.
  3. Choose the service by display name (for example Business Email), environment (live or test), optional expiry, optional IP allowlist, and permissions.
  4. Copy the plaintext secret immediately—it is shown once. Store it as an environment variable on your server or agent worker.

Authenticate requests

Authorization: Bearer <token>
# or
X-API-Key: <token>

Base URL (production): https://umneyconnect.com/api

Successful and failed calls return X-Request-ID. Rate limits on /api/v1/* are 600 requests/minute per API key (plus per-route IP limits). HTTP 429 includes Retry-After and X-RateLimit-* headers.

Key formats

ServicePermissionsExample prefix (live)
Live Chatchat:read, chat:write, visitors:read, webhooks:manageumk_live_<prefix>_…
Business Emailemail:send, email:readumk_live_email_<prefix>_…
AI Agentai:invokeumk_live_ai_<prefix>_…
Business Callingvoice:readumk_live_voice_<prefix>_…
Marketingmarketing:sendumk_live_marketing_<prefix>_…
Automationsautomations:manageumk_live_automations_<prefix>_…
Transactionaltransactional:sendumk_live_transactional_<prefix>_…
Commercecommerce:readumk_live_commerce_<prefix>_…
Analyticsanalytics:readumk_live_analytics_<prefix>_…

In Dashboard → Developers, choose the service name (for example Business Email or Live Chat)—not an internal catalog code. Live Chat live keys use umk_live_<8>_<secret>. Other services (and Live Chat test) use umk_{env}_{suite}_<8>_<secret>.

Agent / Nest pattern

Give the agent a token for only the services it must call. Example: Nest Safety needs Live Chat session minting—create a Live Chat token with chat:write, store it as CONNECT_API_KEY, and never ship it to the mobile app.

# Server / agent environment
CONNECT_API_BASE=https://umneyconnect.com/api
CONNECT_API_KEY=umk_live_…   # Live Chat only

# Agent workflow
# 1. Read /llms.txt
# 2. Open /developers/live-chat for endpoint details
# 3. Call POST /v1/chat/sessions with the token
# 4. Return chatUrl to the end-user client

Errors

{
  "statusCode": 403,
  "error": "Forbidden",
  "message": "API key lacks required scope: chat:write",
  "requestId": "…"
}

Common causes: missing Billing entitlement, wrong product token, missing scope, IP allowlist miss, or expired key. Rotate from Dashboard → Developers without changing your integration code beyond the secret value.