Authentication
Create a personal API token and send it as a bearer token.
The API authenticates with a bearer token. Send it on every request:
Authorization: Bearer <token>Creating a token
Create a personal API token from your account settings, or with the API itself:
curl -X POST https://nextgenpanel.cloudshope.com/api/v1/api-tokens \
-H "Authorization: Bearer <a session or existing token>" \
-H "Content-Type: application/json" \
-d '{ "name": "Order webhook", "expiry": "365d" }'{
"data": {
"id": 42,
"name": "Order webhook",
"token": "cs_live_9f2c…",
"expires_at": "2027-09-08T00:00:00.000Z"
}
}`expiry` is one of:
- `1d` — one day
- `7d` — one week
- `30d` — one month
- `365d` — one year
The raw token is shown once, on creation, and never again. Store it somewhere safe. If you lose it, revoke it from settings and create another.
Using the token
curl https://nextgenpanel.cloudshope.com/api/v1/sms/campaigns \
-H "Authorization: Bearer cs_live_9f2c…"A session token from a browser login works in the same header, but a personal API token is what you want for server-to-server calls — it lasts as long as its expiry rather than expiring with the browser session.
Keep it secret
- Use the token server-side only. Never ship it in frontend code, a repository or a URL.
- Create one token per integration, so you can revoke one without breaking the others.
- Revoke a token the moment it is no longer needed, from your account settings.
| Response | Meaning |
|---|---|
| 401 unauthorized | Header missing or malformed, or the token is invalid or expired. |
| 403 forbidden | Token is valid, but the account cannot perform this action. |
