Integrations
Rotating an integration key without downtime
Implementation scenario · This is an example implementation, not a story about a named customer. Results depend on your integration, phone, network and carrier.
AI-generated scenario illustrationThe problem
A key expires or needs replacement while order notifications must continue. The cutover sequence matters.
Build the solution
Create a new key with the required permissions and expiry. Update your integration’s server secret, test a safe request, then revoke the old key. Do not restore a revoked secret during an automatic rollback.
Check before launch
Check background workers as well as the web server. A 401 after cutover may mean some jobs still use the old secret.
How SIM Bridge works
Your backend creates a job through the API, and the connected Android sends SMS through your SIM. Store the message ID in your system and receive status changes through a webhook. A queued job is not yet a sent message: the phone must be available and the carrier must accept it.
Start with your own test number. Check Android permissions, screen-off connectivity, retries with the same Idempotency-Key, and unknown-status handling. Keep API keys out of browser code and public repositories.