Back to Developer Help
1

Authentication

Activate a device, then generate API keys for programmatic access.

Password sign-in has been retired. The old /api/v1/auth/register and /api/v1/auth/login endpoints now answer 410 AUTH_METHOD_RETIRED and are removed in the release after this one. To get an API key: register a device, verify its SIM, bind an email to activate it, then create keys from the Settings panel (Settings → API Keys) or POST /api/v1/auth/api-keys.

Endpoint

POST /api/v1/phones/register-device No authentication required

Request Body

Field Type
phone_number string (E.164 format, e.g. +15550001234)
country_code string (optional, ISO 3166-1 alpha-2)
label string (optional, display name)

Common Error Responses

429 RATE_LIMITED

Too many verification requests for this number.

Code Samples

# Password sign-in is retired; these two answer 410 AUTH_METHOD_RETIRED.
# Activate a device instead: register its number, verify the SIM, then bind an email.
curl -X POST https://api.palmtext.com/api/v1/phones/register-device \
  -H 'Content-Type: application/json' \
  -d '{"phone_number": "+15550001234", "country_code": "US"}'

# Bind an email to activate the device (the code arrives by email)
curl -X POST https://api.palmtext.com/api/v1/auth/bind/request-code \
  -H 'X-API-Key: YOUR_DEVICE_KEY' \
  -H 'Content-Type: application/json' \
  -d '{"email": "[email protected]"}'

# Create an account-wide API key once the device is activated
curl -X POST https://api.palmtext.com/api/v1/auth/api-keys \
  -H 'X-API-Key: YOUR_DEVICE_KEY' \
  -H 'Content-Type: application/json' \
  -d '{"name": "My App"}'
import requests

# Password sign-in is retired; these answer 410 AUTH_METHOD_RETIRED.
# Activate a device instead: register its number, verify the SIM, bind an email.
resp = requests.post(
    'https://api.palmtext.com/api/v1/phones/register-device',
    json={'phone_number': '+15550001234', 'country_code': 'US'}
)
print(resp.json())

# Bind an email to activate the device
resp = requests.post(
    'https://api.palmtext.com/api/v1/auth/bind/request-code',
    headers={'X-API-Key': 'YOUR_DEVICE_KEY'},
    json={'email': '[email protected]'}
)
print(resp.json())

# Create an account-wide API key once the device is activated
resp = requests.post(
    'https://api.palmtext.com/api/v1/auth/api-keys',
    headers={'X-API-Key': 'YOUR_DEVICE_KEY'},
    json={'name': 'My App'}
)
print(resp.json())
// Password sign-in is retired; these answer 410 AUTH_METHOD_RETIRED.
// Activate a device instead: register its number, verify the SIM, bind an email.
const res = await fetch('https://api.palmtext.com/api/v1/phones/register-device', {
  method: 'POST',
  headers: { 'Content-Type': 'application/json' },
  body: JSON.stringify({ phone_number: '+15550001234', country_code: 'US' })
});
const data = await res.json();

// Bind an email to activate the device
await fetch('https://api.palmtext.com/api/v1/auth/bind/request-code', {
  method: 'POST',
  headers: { 'X-API-Key': 'YOUR_DEVICE_KEY', 'Content-Type': 'application/json' },
  body: JSON.stringify({ email: '[email protected]' })
});

// Create an account-wide API key once the device is activated
await fetch('https://api.palmtext.com/api/v1/auth/api-keys', {
  method: 'POST',
  headers: { 'X-API-Key': 'YOUR_DEVICE_KEY', 'Content-Type': 'application/json' },
  body: JSON.stringify({ name: 'My App' })
});
<?php
$ch = curl_init();

// Password sign-in is retired; these answer 410 AUTH_METHOD_RETIRED.
// Activate a device instead: register its number, verify the SIM, bind an email.
curl_setopt_array($ch, [
  CURLOPT_URL => 'https://api.palmtext.com/api/v1/phones/register-device',
  CURLOPT_POST => true,
  CURLOPT_HTTPHEADER => ['Content-Type: application/json'],
  CURLOPT_POSTFIELDS => json_encode(['phone_number' => '+15550001234', 'country_code' => 'US']),
  CURLOPT_RETURNTRANSFER => true,
]);
$resp = curl_exec($ch);
echo $resp;

// Create an account-wide API key once the device is activated
curl_setopt_array($ch, [
  CURLOPT_URL => 'https://api.palmtext.com/api/v1/auth/api-keys',
  CURLOPT_HTTPHEADER => ['X-API-Key: YOUR_DEVICE_KEY', 'Content-Type: application/json'],
  CURLOPT_POSTFIELDS => json_encode(['name' => 'My App']),
]);
$resp = curl_exec($ch);
echo $resp;
curl_close($ch);
package main

import (
  "bytes"
  "encoding/json"
  "fmt"
  "net/http"
)

// Password sign-in is retired: those endpoints answer 410 AUTH_METHOD_RETIRED.
// Activate a device first, then create an API key with its credential.
func main() {
  body, _ := json.Marshal(map[string]string{
    "phone_number": "+15550001234", "country_code": "US",
  })
  resp, _ := http.Post(
    "https://api.palmtext.com/api/v1/phones/register-device",
    "application/json", bytes.NewBuffer(body),
  )
  defer resp.Body.Close()
  fmt.Println(resp.Status)
}