{"templateId":"markdown","sharedDataIds":{"sidebar":"sidebar-docs/identity-access-management/sidebars.yaml"},"props":{"metadata":{"markdoc":{"tagList":["partial","admonition"]},"type":"markdown"},"seo":{"title":"Authentication methods | Sinch","siteUrl":"https://developers.sinch.com","llmstxt":{"title":"Sinch Developer Documentation","description":"LLMs.txt containing a map of all the documentation files for Sinch.","sections":[{"title":"Numbers API","description":"The Numbers API enables you to search for, view, and activate numbers. It's considered a precursor to other APIs in the Sinch product family. The numbers API can be used in tandem with any of our APIs that perform messaging or calling.","includeFiles":["docs/numbers/**/*.md","docs/numbers/**/*.yaml"],"excludeFiles":["docs/numbers/index.md"]},{"title":"Conversation API","description":"Send and receive messages globally on many popular channels with ease and confidence when using Sinch's Conversation API. Conversation API is the preferred API for sending mobile messages on SMS and other social channels with Sinch. It is a simple API with unified error messages, consistent request payloads, and common webhook payloads that are channel-agnostic.","includeFiles":["docs/conversation/**/*.md","docs/conversation/**/*.yaml"],"excludeFiles":["docs/conversation/index.md"]},{"title":"Voice API","description":"The Voice API works as a big telephony switch. The Voice API handles incoming phone calls (also known as incoming call “legs”), sets up outgoing phone calls (or outgoing call “legs”), and bridges the two. The incoming call leg may come in over a data connection (from a smartphone or web application using the Sinch SDKs) or through a local phone number (from the PSTN network). Similarly, the outgoing call leg can be over data (to another smartphone or web application using the Sinch SDKs) or the PSTN network.","includeFiles":["docs/voice/**/*.md","docs/voice/**/*.yaml"],"excludeFiles":["docs/voice/index.md"]},{"title":"Verification API","description":"The Verification API is a platform for phone number verification. It consists of the API and different software development kits (the Sinch SDKs) that you integrate with your smartphone or web application and cloud based back-end services. Together they enable SMS, Flashcall, Phone Call and Data verification in your application.","includeFiles":["docs/verification/**/*.md","docs/verification/**/*.yaml"],"excludeFiles":["docs/verification/index.md"]},{"title":"Provisioning API","description":"Provisioning API allows you to programmatically set up your senders, accounts and templates on your favorite messaging platforms on the Conversation API. For now, you can create your first WhatsApp channel through Meta's Embedded sign up, you can configure your first SMS App and configure your webhooks. As development continues, we will be adding the most commonly used channels.","includeFiles":["docs/provisioning-api/**/*.md","docs/provisioning-api/**/*.json"],"excludeFiles":["docs/provisioning-api/index.md"]},{"title":"Elastic SIP Trunking API","description":"With Elastic SIP Trunking you can create and manage your SIP trunks and phone numbers programmatically.","includeFiles":["docs/est/**/*.md","docs/est/**/*.yaml"],"excludeFiles":["docs/est/index.md"]},{"title":"Fax API","description":"Send and receive HIPAA compliant faxes on our modern fax platform using our developer-friendly API.","includeFiles":["docs/fax/**/*.md","docs/fax/**/*.yaml"],"excludeFiles":["docs/fax/index.md"]},{"title":"In-app Voice and Video SDK","description":"The In-app Voice and Video SDK enables you to add voice and video calling capabilities directly into your mobile or web application using the Sinch SDKs.","includeFiles":["docs/in-app-calling/**/*.md"],"excludeFiles":["docs/in-app-calling/index.md"]},{"title":"Number Lookup API","description":"The Number Lookup API is designed to provide in-depth information about phone numbers, helping enterprises enhance their communication strategies and prevent fraud. By identifying the type of phone line (for example, mobile, landline, VoIP) and the associated carrier, the API allows businesses to optimize routing, reduce unnecessary costs, and improve customer engagement.","includeFiles":["docs/number-lookup-api-v2/**/*.md","docs/number-lookup-api-v2/**/*.yaml"],"excludeFiles":["docs/number-lookup-api-v2/index.md"]},{"title":"Functions","description":"Serverless compute for voice and messaging. Deploy your code and Sinch routes live calls and messages to it — no infrastructure to run.","includeFiles":["docs/functions/functions/**/*.md","docs/functions/concepts/**/*.md","docs/functions/reference/**/*.md"],"excludeFiles":["docs/functions/functions/index.md"]},{"title":"CLI","description":"One command line for every Sinch API and the full Functions lifecycle — scaffold, run locally, deploy, and manage.","includeFiles":["docs/functions/cli/**/*.md"],"excludeFiles":["docs/functions/cli/index.md"]}]},"description":"Learn about how to authenticate with Sinch APIs."},"dynamicMarkdocComponents":[],"compilationErrors":[],"ast":{"$$mdtype":"Tag","name":"article","attributes":{},"children":[{"$$mdtype":"Tag","name":"Heading","attributes":{"level":1,"id":"authentication-methods","__idx":0},"children":["Authentication methods"]},{"$$mdtype":"Tag","name":"p","attributes":{},"children":[{"$$mdtype":"Tag","name":"ConnectButton","attributes":{"title":"Sinch Agentic Tools","icon":"aiCode","option":[{"title":"Sinch Plugins","description":"Install Sinch Plugins","icon":"connection","link":"https://github.com/sinch/sinch-plugins#installation"},{"title":"Sinch Skills","description":"Install Sinch Skills","icon":"ai","link":"https://github.com/sinch/skills#installation"}]},"children":[]}," ",{"$$mdtype":"Tag","name":"ConnectButton","attributes":{"title":"Sinch SDKs","icon":"code","option":[{"title":"Sinch Node.js SDK","description":"Install Sinch Node.js SDK","icon":"node","link":"/docs/sdks/node#installation"},{"title":"Sinch Java SDK","description":"Install Sinch Java SDK","icon":"java","link":"/docs/sdks/java#installation"},{"title":"Sinch .NET SDK","description":"Install Sinch .NET SDK","icon":"dotnet","link":"/docs/sdks/dotnet#installation"},{"title":"Sinch Python SDK","description":"Install Sinch Python SDK","icon":"python","link":"/docs/sdks/python#installation"}]},"children":[]}," ",{"$$mdtype":"Tag","name":"ConnectButton","attributes":{"title":"Sinch CLI & Functions","icon":"window","option":[{"title":"Sinch CLI","description":"Install Sinch CLI","icon":"cli","link":"/docs/functions/cli/installation"},{"title":"Sinch Functions","description":"Quickstart Sinch Functions","icon":"code","link":"/docs/functions/functions/quickstart"}]},"children":[]}," ",{"$$mdtype":"Tag","name":"ConnectMCP","attributes":{"placement":"bottom","alignment":"start","options":["cursor","vscode","copy"]},"children":[]}]},{"$$mdtype":"Tag","name":"p","attributes":{},"children":["For credentials specific to the SMS, Voice, or Verification APIs, see the ",{"$$mdtype":"Tag","name":"MarkdownLink","attributes":{"href":"#product-specific-credentials"},"children":["Product-specific credentials"]}," section at the end of this page."]},{"$$mdtype":"Tag","name":"Admonition","attributes":{"type":"info","name":"Note:"},"children":[{"$$mdtype":"Tag","name":"p","attributes":{},"children":["You create and manage all of these credentials yourself in the Sinch Build Dashboard."]}]},{"$$mdtype":"Tag","name":"Heading","attributes":{"level":3,"id":"oauth2-access-tokens-sinchapis","__idx":1},"children":["OAuth2 access tokens (SinchAPIs)"]},{"$$mdtype":"Tag","name":"p","attributes":{},"children":["This is the modern, recommended path and the ones most Sinch APIs use."]},{"$$mdtype":"Tag","name":"ol","attributes":{},"children":[{"$$mdtype":"Tag","name":"li","attributes":{},"children":[{"$$mdtype":"Tag","name":"p","attributes":{},"children":["Create an access key in your project. You get a Key ID and a Key Secret. See Access keys."]}]},{"$$mdtype":"Tag","name":"li","attributes":{},"children":[{"$$mdtype":"Tag","name":"p","attributes":{},"children":["Exchange the key for a short-lived OAuth2 bearer token using the client credentials grant. See OAuth2 access tokens."]}]},{"$$mdtype":"Tag","name":"li","attributes":{},"children":[{"$$mdtype":"Tag","name":"p","attributes":{},"children":["Send the token on every request:"]},{"$$mdtype":"Tag","name":"CodeBlock","attributes":{"data-language":"shell","header":{"controls":{"copy":{}}},"source":"curl https://numbers.api.sinch.com/v1/projects/YOUR_project_id/availableNumbers \\\n-H \"Authorization: Bearer YOUR_access_token\"\n","lang":"shell"},"children":[]}]}]},{"$$mdtype":"Tag","name":"Admonition","attributes":{"type":"info","name":"Tip:"},"children":[{"$$mdtype":"Tag","name":"p","attributes":{},"children":["Tokens are short-lived. Cache a token and reuse it until it expires rather than requesting a new one per call. Details in ",{"$$mdtype":"Tag","name":"MarkdownLink","attributes":{"href":"/docs/identity-access-management/authenticate/oauth2"},"children":["OAuth2 access tokens"]},"."]}]},{"$$mdtype":"Tag","name":"Heading","attributes":{"level":2,"id":"product-specific-credentials","__idx":2},"children":["Product-specific credentials"]},{"$$mdtype":"Tag","name":"p","attributes":{},"children":["The following authentication methods apply to specific Sinch products."]},{"$$mdtype":"Tag","name":"Heading","attributes":{"level":3,"id":"sms-service-plan-id--api-token","__idx":3},"children":["SMS: Service Plan ID + API token"]},{"$$mdtype":"Tag","name":"p","attributes":{},"children":["The SMS API authenticates with a Service Plan ID and an API token, both created automatically when you set up SMS in the dashboard."]},{"$$mdtype":"Tag","name":"CodeBlock","attributes":{"data-language":"shell","header":{"controls":{"copy":{}}},"source":"curl https://us.sms.api.sinch.com/xms/v1/YOUR_service_plan_id/batches \\\n  -H \"Authorization: Bearer YOUR_api_token\" \\\n  -H \"Content-Type: application/json\"\n","lang":"shell"},"children":[]},{"$$mdtype":"Tag","name":"div","attributes":{"className":"md-table-wrapper"},"children":[{"$$mdtype":"Tag","name":"table","attributes":{"className":"md"},"children":[{"$$mdtype":"Tag","name":"thead","attributes":{},"children":[{"$$mdtype":"Tag","name":"tr","attributes":{},"children":[{"$$mdtype":"Tag","name":"th","attributes":{"data-label":"Placeholder"},"children":["Placeholder"]},{"$$mdtype":"Tag","name":"th","attributes":{"data-label":"Description"},"children":["Description"]}]}]},{"$$mdtype":"Tag","name":"tbody","attributes":{},"children":[{"$$mdtype":"Tag","name":"tr","attributes":{},"children":[{"$$mdtype":"Tag","name":"td","attributes":{},"children":[{"$$mdtype":"Tag","name":"code","attributes":{},"children":["YOUR_service_plan_id"]}]},{"$$mdtype":"Tag","name":"td","attributes":{},"children":["Identifies your SMS service plan. Find it in the dashboard under SMS."]}]},{"$$mdtype":"Tag","name":"tr","attributes":{},"children":[{"$$mdtype":"Tag","name":"td","attributes":{},"children":[{"$$mdtype":"Tag","name":"code","attributes":{},"children":["YOUR_api_token"]}]},{"$$mdtype":"Tag","name":"td","attributes":{},"children":["The token used to authenticate SMS calls. Listed alongside your Service Plan ID."]}]}]}]}]},{"$$mdtype":"Tag","name":"Admonition","attributes":{"type":"info","name":"Note:"},"children":[{"$$mdtype":"Tag","name":"p","attributes":{},"children":["SMS uses regional hosts (for example ",{"$$mdtype":"Tag","name":"code","attributes":{},"children":["us."]}," or ",{"$$mdtype":"Tag","name":"code","attributes":{},"children":["eu."]},"). Use the host that matches the region where your service plan was created."]}]},{"$$mdtype":"Tag","name":"Heading","attributes":{"level":3,"id":"voice--verification-application-key--secret","__idx":4},"children":["Voice & Verification: application key + secret"]},{"$$mdtype":"Tag","name":"p","attributes":{},"children":["The Voice API and the classic Verification API authenticate at the application level using an application key and application secret. They support HTTP Basic authentication and a signed-request scheme for higher security."]},{"$$mdtype":"Tag","name":"CodeBlock","attributes":{"data-language":"shell","header":{"controls":{"copy":{}}},"source":"curl https://calling.api.sinch.com/calling/v1/callouts \\\n  -u \"YOUR_application_key:YOUR_application_secret\" \\\n  -H \"Content-Type: application/json\"\n","lang":"shell"},"children":[]},{"$$mdtype":"Tag","name":"div","attributes":{"className":"md-table-wrapper"},"children":[{"$$mdtype":"Tag","name":"table","attributes":{"className":"md"},"children":[{"$$mdtype":"Tag","name":"thead","attributes":{},"children":[{"$$mdtype":"Tag","name":"tr","attributes":{},"children":[{"$$mdtype":"Tag","name":"th","attributes":{"data-label":"Placeholder"},"children":["Placeholder"]},{"$$mdtype":"Tag","name":"th","attributes":{"data-label":"Description"},"children":["Description"]}]}]},{"$$mdtype":"Tag","name":"tbody","attributes":{},"children":[{"$$mdtype":"Tag","name":"tr","attributes":{},"children":[{"$$mdtype":"Tag","name":"td","attributes":{},"children":[{"$$mdtype":"Tag","name":"code","attributes":{},"children":["YOUR_application_key"]}]},{"$$mdtype":"Tag","name":"td","attributes":{},"children":["Your app's key, found in the dashboard under the app's settings."]}]},{"$$mdtype":"Tag","name":"tr","attributes":{},"children":[{"$$mdtype":"Tag","name":"td","attributes":{},"children":[{"$$mdtype":"Tag","name":"code","attributes":{},"children":["YOUR_application_secret"]}]},{"$$mdtype":"Tag","name":"td","attributes":{},"children":["Your app's secret. Treat it like a password."]}]}]}]}]},{"$$mdtype":"Tag","name":"Heading","attributes":{"level":2,"id":"keep-credentials-safe","__idx":5},"children":["Keep credentials safe"]},{"$$mdtype":"Tag","name":"p","attributes":{},"children":["Whichever method you use, the same rules apply:"]},{"$$mdtype":"Tag","name":"ul","attributes":{},"children":[{"$$mdtype":"Tag","name":"li","attributes":{},"children":["Never commit secrets to source control or expose them in client-side code."]},{"$$mdtype":"Tag","name":"li","attributes":{},"children":["Store secrets in a secrets manager or environment variables."]},{"$$mdtype":"Tag","name":"li","attributes":{},"children":["Rotate credentials periodically and immediately if one may be exposed."]},{"$$mdtype":"Tag","name":"li","attributes":{},"children":["Scope access keys to the narrowest project that needs them."]}]},{"$$mdtype":"Tag","name":"p","attributes":{},"children":["See ",{"$$mdtype":"Tag","name":"MarkdownLink","attributes":{"href":"/docs/identity-access-management/access/access-keys"},"children":["Access keys"]}," for rotation and storage guidance."]}]},"headings":[{"value":"Authentication methods","id":"authentication-methods","depth":1},{"value":"OAuth2 access tokens (SinchAPIs)","id":"oauth2-access-tokens-sinchapis","depth":3},{"value":"Product-specific credentials","id":"product-specific-credentials","depth":2},{"value":"SMS: Service Plan ID + API token","id":"sms-service-plan-id--api-token","depth":3},{"value":"Voice & Verification: application key + secret","id":"voice--verification-application-key--secret","depth":3},{"value":"Keep credentials safe","id":"keep-credentials-safe","depth":2}],"frontmatter":{"seo":{"title":"Authentication methods | Sinch","description":"Learn about how to authenticate with Sinch APIs."}},"lastModified":"2026-08-18T14:45:01.000Z","pagePropGetterError":{"message":"","name":""}},"slug":"/docs/identity-access-management/authenticate/authentication","userData":{"isAuthenticated":false,"teams":["anonymous"]},"isPublic":true}