Authentication
Get an API key from the Webhook integration and authenticate requests to the Helios API.
Every request to the Helios API is authenticated with a Bearer token. The token is an API key that belongs to a Webhook integration on one of your inboxes.
Get an API key
Open Integrations
In the Helios dashboard, go to Integrations and open the Webhook integration.
Install it
Installing the Webhook integration on an inbox generates an API key for that inbox.
Copy the key
Copy the key from the integration’s settings. Treat it like a password: it can read and change the inbox’s contacts, conversations, and messages, and send texts on its behalf.
Each key is scoped to the inbox it was created for. Requests for contacts, threads, or messages in another inbox are rejected, even within the same organization. To work with several inboxes, create a key for each one.
Authenticate a request
Send the key in the Authorization header:
curl https://api.sendhelios.com/v1/gyms \
-H "Authorization: Bearer YOUR_API_KEY"
Verify your key
Use the verify endpoint to confirm a key is valid before wiring it into your system. It responds 200 with the key’s integration details when the key is valid and active, 401 when the key is missing or not recognized, and 403 when the integration has been turned off:
curl https://api.sendhelios.com/v1/auth/verify \
-H "Authorization: Bearer YOUR_API_KEY"
Both GET and POST are supported, so the endpoint also works as a connection test target for platforms that require one.
Errors
Error responses have a JSON body with status and message.
| Status | Meaning |
|---|---|
401 |
The API key is missing or not recognized. |
403 |
The integration is inactive, or the contact, thread, or message belongs to a different inbox. |
422 |
A parameter is invalid, for example an unknown filter or a limit above 1000. |
Base URL
All endpoints live under:
https://api.sendhelios.com
Browse every endpoint in the API reference.