Skip to main content
Every request carries two things: the shared API key, and the PowerDialer user the request acts for. The user is looked up in PowerDialer’s identity provider on each request and cached for five minutes. All reads and writes are then limited to lists that user owns. If both user headers are sent, x-user-id wins.
Keep the key on your server. Anyone holding it can act for any user. Never embed it in a browser, mobile app or client-side code. Ask PowerDialer to rotate it if it is ever exposed — two keys can be valid during a rotation.

Authentication errors

A 502 is transient — retry later. A 404 User not found means the email or id does not match a PowerDialer account; check the spelling or use the other header.