← All articles

Integrations

Access keys with minimum permissions

Implementation scenario · This is an example implementation, not a story about a named customer. Results depend on your integration, phone, network and carrier.

Access keys with minimum permissionsAI-generated scenario illustration

The problem

A notification key does not always need device or webhook management. Broad permissions make a leaked key more damaging.

Build the solution

Choose only required actions when issuing a key: sending SMS, reading statuses and viewing devices. Use separate keys for integrations, set an expiry and keep the secret server-side. Its full value is shown only at creation.

Check before launch

Verify that revoked keys stop working. Rotate before expiry and keep keys out of URLs, screenshots and client-side settings.

How SIM Bridge works

Your backend creates a job through the API, and the connected Android sends SMS through your SIM. Store the message ID in your system and receive status changes through a webhook. A queued job is not yet a sent message: the phone must be available and the carrier must accept it.

Start with your own test number. Check Android permissions, screen-off connectivity, retries with the same Idempotency-Key, and unknown-status handling. Keep API keys out of browser code and public repositories.

Start free ↗

Related reading

Connect your work phone to your system

Start with Free and test one workflow on your Android.

Start free ↗