> ## Documentation Index
> Fetch the complete documentation index at: https://docs.verisoul.ai/llms.txt
> Use this file to discover all available pages before exploring further.

# API Keys and Webhooks

> Manage project API keys and signed webhooks

API keys let your backend call the Verisoul API for one project. Webhooks send a project's events to your endpoint, signed so you can verify they came from Verisoul. Both are managed under **Settings**, in tables covering every project you can access.

The keys on this page are project API keys. Keys for AI clients are separate; see [MCP Access](/dashboard/mcp-access).

## API keys

A project API key has full access to the Verisoul API for its project, including the **Allow** and **Block** lists. Send it in the `x-api-key` header, as shown in the [API Reference](/api-reference/introduction). Client SDKs identify the project by its Project ID and never need a key.

| Property | Detail |
| - | - |
| Scope | One project, in one environment |
| Format | 40 characters of letters and digits |
| Expiry | None. A key works until it is deleted. |
| Keys per project | Several can be active at once |
| Activation and revocation | Take effect within about a minute |

### Who can see a key

Only people with **Manage API keys** on a key's project (Editors and Admins) can see or copy its full value. Everyone else sees the last four characters. A key grants full API access, so holding it would bypass role limits in the dashboard.

### Rotating a key

1. Create a new key in the same project.
2. Move your integration to the new key and confirm requests succeed.
3. Delete the old key. Deletion cannot be undone.

<Warning>
  Keep at least one key in every project you use. The dashboard also uses a project key for account and session pages, verification sessions, list changes, email submissions and webhook changes. Deleting a project's last key stops those features until a new key is created.
</Warning>

## Webhooks

A webhook sends a `POST` request to your endpoint when a chosen event occurs in a project. **Email Intel Completed** (`email.intelligence.completed`) fires when an email analysis finishes; see the [Webhook Payload Reference](/email-intelligence/webhook-reference).

Each webhook has its own signing secret, shown after creation and available in the table afterwards. Every delivery carries an `x-signature` header made with it. Verify it before trusting a payload, as described in [Webhook Signature Verification](/email-intelligence/webhook-signature-verification).

* A new webhook is enabled when created.
* While a webhook is disabled, events are not delivered, and they are not sent later.
* Creating a webhook needs an API key in the project.

The dashboard creates webhooks and turns them on and off. To change a URL or events, create a new webhook and disable the old one, or use the `webhooks_update` and `webhooks_delete` tools through the [MCP server](/dashboard/mcp-access).

## Permissions

| Action | Viewer | Analyst | Editor |
| - | - | - | - |
| See which API keys and webhooks exist | ✓ | ✓ | ✓ |
| See and copy API key values | | | ✓ |
| Create and delete API keys | | | ✓ |
| Create webhooks and turn them on or off | | | ✓ |

Admins have every permission. Permissions apply per project. See [Managing Users](/dashboard/managing-users).

Keys and webhooks belong to a project, so Sandbox and Production each need their own. A Sandbox key works against `https://api.sandbox.verisoul.ai`, and a Production key against `https://api.prod.verisoul.ai`.

## Need Help?

If you have any questions about API keys and webhooks, please contact our support team at [support@verisoul.ai](mailto:support@verisoul.ai).


This documentation is built and hosted on [Mintlify](https://mintlify.com), a developer documentation platform.