Introduction
Plivo is a robust cloud communications platform that enables businesses and developers to integrate voice calls, SMS, and messaging capabilities directly into their applications. Whether you are building automated SMS notifications, multi-factor authentication systems, or complex voice IVR solutions, interacting with Plivo’s REST API requires authenticating your requests.
In Plivo’s ecosystem, your API key consists of two core credentials: an Auth ID and an Auth Token. Together, these act as your username and password when making API requests. This comprehensive guide walks you through the step-by-step process of signing up for Plivo, retrieving your API credentials, and securing them properly.
Prerequisites Before Getting Started
Before creating your account and generating API credentials, ensure you have the following ready:
- A valid business or personal email address.
- A working mobile phone number capable of receiving SMS messages or voice calls for identity verification.
- A modern web browser with JavaScript enabled.
Step-by-Step Guide: How to Get Your Plivo API Key
Step 1: Visit the Plivo Sign-Up Page
Open your web browser and navigate to the official Plivo website (https://www.plivo.com). Click the Start Free Trial or Sign Up button located in the top right corner of the page.
Step 2: Complete the Registration Form
Fill in the required information on the registration page:
- First and Last Name: Enter your full legal name.
- Work Email: Enter a valid email address. Plivo prefers company domains for account approval, though standard email providers are also supported.
- Password: Create a strong password that meets Plivo’s security criteria (including uppercase letters, numbers, and special characters).
- Company / Organization Name: Enter your business name or personal developer handle.
Review and accept the Terms of Service and Privacy Policy, then click Create Account.
Step 3: Verify Your Email Address
Plivo will send an activation link to the email address provided during registration. Open your inbox, find the verification email from Plivo, and click the confirmation link inside. This will confirm your ownership of the email address and redirect you back to the Plivo activation workflow.
Step 4: Verify Your Phone Number
To prevent misuse and maintain network integrity, Plivo requires phone verification during account creation:
- Select your country code from the dropdown menu.
- Enter your active mobile phone number.
- Choose your preferred verification method: SMS or Voice Call.
- Click Send Verification Code.
- Enter the 6-digit verification code sent to your phone and submit the form.
Step 5: Access the Plivo Console Dashboard
Once phone verification is complete, you will be redirected to the main Plivo Console Dashboard. By default, new accounts start in a trial mode with free test credits, allowing you to test basic functionality right away.
Step 6: Locate Your Auth ID and Auth Token
Finding your API credentials on the dashboard is straightforward:
- On the main Console home page, look at the top section labeled Account Overview or Dashboard Summary.
- Locate the field named Auth ID. This is a public alphanumeric string that identifies your specific account.
- Locate the adjacent field named Auth Token. By default, this value is hidden behind asterisks for security purposes.
- Click the Eye Icon or Show button next to the Auth Token field to reveal the full secret key string.
Together, your Auth ID and Auth Token serve as the primary API key pair for all HTTP requests and official Plivo SDKs (Python, Node.js, PHP, Java, Ruby, Go, and .NET).
How to Rotate or Reset Your Auth Token
If your Auth Token is accidentally leaked, committed to a public repository, or compromised, you must regenerate it immediately to prevent unauthorized access to your account balances and phone numbers.
- Navigate to Account > Settings in the top-right navigation menu.
- Select the Credentials or Security tab.
- Click Rotate Auth Token.
- Confirm the prompt. Plivo will immediately invalidate your old Auth Token and generate a new one.
- Update all production applications with the new token to prevent service interruptions.
Essential Security Best Practices for Your API Credentials
Your Plivo credentials give full administrative control over your cloud communications, including sending paid SMS messages and making outbound calls. Follow these security guidelines to safeguard your account:
- Never Hardcode Credentials: Do not put your Auth ID and Auth Token directly inside client-side JavaScript, mobile app code, or publicly accessible code bases.
- Use Environment Variables: Store credentials in environment variables (such as a
.envfile) on your secure backend server. - Restrict Git Repositories: Ensure files containing credentials (like
.env) are listed in your.gitignorefile before committing code to platform services like GitHub or GitLab. - Implement IP Whitelisting: If supported by your architecture, restrict API requests to specific server IP addresses within your Plivo security settings.
- Set Spending Alerts: Configure balance threshold alerts in the Plivo Console so you are immediately notified of unusual usage spikes or unauthorized account activity.
Next Steps: Testing Your API Credentials
Now that you have secured your Auth ID and Auth Token, you can make your first API request using cURL or any official Plivo helper library. For example, to send a test SMS via cURL, substitute your credentials in the following request structure:
curl -X POST https://api.plivo.com/v1/Account/{YOUR_AUTH_ID}/Message/
-u "{YOUR_AUTH_ID}:{YOUR_AUTH_TOKEN}"
-H "Content-Type: application/json"
-d '{"src": "1111111111", "dst": "2222222222", "text": "Hello from Plivo!"}'
Conclusion
Obtaining your Plivo API key is a simple process that requires only account registration and basic identity verification. By locating your Auth ID and Auth Token within the Plivo Console and implementing strict credential management practices, you can safely integrate reliable voice and messaging capabilities into your software applications.
