API reference

Authentication

Create a personal API token and send it as a bearer token.

The API authenticates with a bearer token. Send it on every request:

Authorization: Bearer <token>

Creating a token

Create a personal API token from your account settings, or with the API itself:

curl -X POST https://nextgenpanel.cloudshope.com/api/v1/api-tokens \
  -H "Authorization: Bearer <a session or existing token>" \
  -H "Content-Type: application/json" \
  -d '{ "name": "Order webhook", "expiry": "365d" }'
{
  "data": {
    "id": 42,
    "name": "Order webhook",
    "token": "cs_live_9f2c…",
    "expires_at": "2027-09-08T00:00:00.000Z"
  }
}
201 Created — the raw token is in `token`, and this is the only response that ever contains it.

`expiry` is one of:

  • `1d` — one day
  • `7d` — one week
  • `30d` — one month
  • `365d` — one year

The raw token is shown once, on creation, and never again. Store it somewhere safe. If you lose it, revoke it from settings and create another.

Using the token

curl https://nextgenpanel.cloudshope.com/api/v1/sms/campaigns \
  -H "Authorization: Bearer cs_live_9f2c…"

A session token from a browser login works in the same header, but a personal API token is what you want for server-to-server calls — it lasts as long as its expiry rather than expiring with the browser session.

Keep it secret

  • Use the token server-side only. Never ship it in frontend code, a repository or a URL.
  • Create one token per integration, so you can revoke one without breaking the others.
  • Revoke a token the moment it is no longer needed, from your account settings.
ResponseMeaning
401 unauthorizedHeader missing or malformed, or the token is invalid or expired.
403 forbiddenToken is valid, but the account cannot perform this action.