API keys
A project API key has full access to the Verisoul API for its project, including the Allow and Block lists. Send it in thex-api-key header, as shown in the API Reference. Client SDKs identify the project by its Project ID and never need a key.
Who can see a key
Only people with Manage API keys on a key’s project (Editors and Admins) can see or copy its full value. Everyone else sees the last four characters. A key grants full API access, so holding it would bypass role limits in the dashboard.Rotating a key
- Create a new key in the same project.
- Move your integration to the new key and confirm requests succeed.
- Delete the old key. Deletion cannot be undone.
Webhooks
A webhook sends aPOST request to your endpoint when a chosen event occurs in a project. Email Intel Completed (email.intelligence.completed) fires when an email analysis finishes; see the Webhook Payload Reference.
Each webhook has its own signing secret, shown after creation and available in the table afterwards. Every delivery carries an x-signature header made with it. Verify it before trusting a payload, as described in Webhook Signature Verification.
- A new webhook is enabled when created.
- While a webhook is disabled, events are not delivered, and they are not sent later.
- Creating a webhook needs an API key in the project.
webhooks_update and webhooks_delete tools through the MCP server.
Permissions
Admins have every permission. Permissions apply per project. See Managing Users.
Keys and webhooks belong to a project, so Sandbox and Production each need their own. A Sandbox key works against
https://api.sandbox.verisoul.ai, and a Production key against https://api.prod.verisoul.ai.
