Authorization header, and every request must be scoped to a specific workspace. Your data is isolated to your workspace — a credential can only access data in workspaces it is authorized for, regardless of how a request is formed.
Credential types
How to pass credentials
Include your credential in theAuthorization header of every API request using the Bearer scheme:
workspace_id in the request body or as a query parameter:
Credential details
User JWT
User JWT
A user JWT is issued when you authenticate through the SendWhale sign-in flow. It represents your personal identity and inherits the permissions of your role in each workspace (owner, admin, editor, or viewer).Use a user JWT when making direct API calls on your own behalf — for example, from a server-side script that you run as yourself.User JWTs are valid for the duration of your session. When the session expires, sign in again to obtain a fresh token.
Workspace API key
Workspace API key
Workspace API keys are long-lived credentials scoped to a specific workspace. Use them for Campaign API and contact operations in server-side integrations where you do not want to rely on a personal session.Create and manage workspace API keys in workspace Settings. Each key can be given a custom expiry and should be rotated regularly. Revoke any key that is no longer in use.
Brand read key
Brand read key
Brand read keys authenticate requests to the Brand Context API. They are intentionally limited in scope:A brand read key can:
- Read workspace brand context (name, description, voice, colors, fonts, social links, knowledge base)
- Send mail
- Read contact lists
- Create or modify campaigns
- Access billing data
Because brand read keys have a limited permission scope, they are safe to use in server-side automation and AI integrations. Store them as server-side environment variables — never in client-side code or public repositories.
MCP access token
MCP access token
The local MCP server authenticates using your personal user JWT — the same token issued when you sign in to SendWhale. This is intentional: MCP operations act on your behalf within your role’s permissions, so the server never needs a separate service-level credential.Supply your user JWT as the
SENDWHALE_ACCESS_TOKEN environment variable when configuring the MCP server. See the MCP overview for full configuration instructions.Credential expiry and rotation
Rotate credentials proactively rather than reactively. If any credential is exposed or compromised, revoke it immediately from workspace Settings and replace it before resuming operations.