Skip to content
cleo.Developers
Get started/Authentication
Cleo documentation

Authentication

Create a key in Cleo and authenticate requests with a bearer token.

Content reviewed · Maintained by Cleo Powered · Report a documentation issue · Verification basis

Verify your US phone before using the API. Muse and other execution-capable bots can register your account and obtain a key with your consent. You can also sign up in Cleo and create a key in Settings. Every call still requires your authorization. Learn about API access.

Create a key

  1. Sign in to Cleo Settings → API.
  2. Choose New API key, enter a name and expiration, then select Create. Complete assistant setup first if key creation is unavailable.
  3. Copy the full key immediately. Store it in your server’s secret manager or enter it at a hidden local prompt.

A key looks like nd_sk_<public-id>_<secret>. A platform login session is a different credential and cannot replace this API key.

Authenticate every call request

HTTP header
Authorization: Bearer <API_KEY>

Make requests from your server or a local script. Keep the key out of frontend JavaScript, source control, URLs, and logs. The examples read CLEO_API_KEY from your environment or use a hidden prompt.

Set a descriptive User-Agent, such as CleoDocs/1.0. Python’s default client signature may be rejected by the site’s traffic filter.

Value
CLEO_API_KEY
Where it comes from
A secret credential created in Settings, sent in Authorization.
When to reuse it
Across calls until it expires or is revoked.
Value
IDEMPOTENCY_KEY
Where it comes from
An identifier you generate before creation, sent in Idempotency-Key.
When to reuse it
Only for retries of the same intended call with the same payload.
Value
CALL_ID
Where it comes from
The id returned by the create response.
When to reuse it
To get, sync, or cancel that existing call.

These values are not interchangeable. Health checks require none of them.

Workspace and key ownership

Each key belongs to an Agent Project: the group that ties keys to your workspace assistant and its API calls. Cleo creates this group automatically when saving your first task or completing assistant setup; you do not need to create a project manually.

  • Keys from the same project share access to its calls and idempotency history.
  • A key from another project cannot read or cancel those calls.
  • API-created tasks and calls are visible in the owning workspace’s platform history.

Rotate a key

  1. Create a replacement key.
  2. Update your application to use it and verify a request.
  3. Revoke the old key in Settings.

Revoking the original key can prevent its queued work from being dispatched. It does not itself cancel a call already in progress. Keep a working key from the same project to read, sync, or cancel them.

Revoked and expired keys return 401. Key validation happens on each API operation, so revoking a key prevents subsequent requests with it.

Documentation
Get an API key

Explore the docs

IntroductionSubmit a phone errand, follow the call, and inspect its outcome.Bot account onboardingRegister from Muse or another bot, verify your phone, receive an API key, and set your dashboard password by email.API overviewWhich endpoints are available, how they authenticate, and what is supported today.Make your first callCall your own phone, refresh its status, and inspect the returned call data.AuthenticationCreate a key in Cleo and authenticate requests with a bearer token.Create a callQueue one bounded phone task and receive durable task and call IDs.Get a callRead the most recently saved state of a call.Sync a callRefresh a call from the calling service and retrieve its latest saved state.Cancel a callCancel queued work or request a stop, then follow confirmation.The call objectThe shared response returned by create, get, sync, and cancel.Health checksCheck API liveness and readiness without an API key or placing a call.Results & schemasUnderstand result_schema, returned metadata, and what result_schema_valid does and does not establish.Task and call lifecycleFollow a call from acceptance to its final outcome.Idempotency & retriesRecover from an interrupted request without accidentally placing a second call.Safety & permissionsHow Cleo evaluates a call task before it can dial.Errors & troubleshootingUnderstand API errors and choose a safe next step.LimitsKeep call tasks bounded and leave room for API rate limits.Verification & limitationsReproduce our public health and schema checks and understand what has not been tested.Bot integrationsChoose a route for connecting your assistant to Cleo's public API.ChatGPTConfigure a private GPT Action with Cleo OpenAPI and bearer authentication.ClaudeConnect Claude client tools or a Claude Code shell workflow.Grok & Grok BotConnect xAI function tools and check Grok Bot execution requirements.OpenClawInstall a local skill for an approved Cleo calling workflow.GeminiMap Gemini function declarations to Cleo REST operations.Copilot StudioAdd Cleo through a REST API tool, custom connector, or flow.n8nBuild an authenticated HTTP workflow with durable call recovery.ZapierBuild a private Zapier integration for approved Cleo calls.