Twilio Auth Tokens API

Manage primary and secondary auth tokens

Business capability
Developer Identity & Credential Management BC-4270.40

Operations 6

Each operation below carries the questions people ask an LLM about it and the instructions they give an agent to run it. Generated by API Evangelist overlay

POST /AuthTokens/Promote Promote the secondary auth token (legacy path) · Twilio Promote Secondary Auth Token #
Ask an LLM
“Can I promote my secondary auth token through the older unversioned endpoint?”
“Does the legacy promote call invalidate my old primary token immediately?”
Tell an agent destructive · confirm first
Promote my secondary auth token to primary using the legacy endpoint.
Call the unversioned /AuthTokens/Promote path to swap in the secondary token.
POST /AuthTokens/Secondary Create a secondary auth token (legacy path) · Twilio Create a Secondary Auth Token #
Ask an LLM
“Can I create a secondary auth token through the legacy unversioned endpoint?”
“Is the older secondary token endpoint still usable for zero-downtime rotation?”
Tell an agent
Create a secondary auth token via the legacy endpoint.
Generate a backup token using the unversioned /AuthTokens/Secondary path.
DELETE /AuthTokens/Secondary Delete the secondary auth token (legacy path) · Twilio Delete the Secondary Auth Token #
Ask an LLM
“Can I delete my secondary auth token through the older unversioned path?”
“Is there a legacy call to discard a secondary token I created by mistake?”
Tell an agent destructive · confirm first
Delete my secondary auth token via the legacy endpoint.
Discard the backup token using the unversioned /AuthTokens/Secondary path.
POST /v1/AuthTokens/Promote Promote the secondary auth token to primary · Update auth token promotion #
Ask an LLM
“How do I finish rotating my auth token once the new one is deployed everywhere?”
“What happens to requests signed with my old primary auth token after a promotion?”
Tell an agent destructive · confirm first
Promote my secondary auth token to primary with the v1 API.
Complete my auth token rotation so the old primary stops working.
POST /v1/AuthTokens/Secondary Create a new secondary auth token · Create secondary auth token #
Ask an LLM
“Can I rotate my auth token without downtime by creating a second one first?”
“Where do I get a fresh secondary auth token for my account?”
Tell an agent
Create a new secondary auth token with the v1 API.
Start an auth token rotation by issuing a secondary token.
DELETE /v1/AuthTokens/Secondary Delete the secondary auth token · Delete secondary auth token #
Ask an LLM
“Can I cancel a token rotation by deleting the secondary token?”
“Which call removes a secondary auth token that leaked?”
Tell an agent destructive · confirm first
Delete my secondary auth token with the v1 API.
Abort the auth token rotation and throw away the secondary token.

Documentation

Specifications

Other Resources

Work with this as data

Every API here is available over the APIs.io API and to AI agents over MCP.

MCP server

One button, every client — Claude, Cursor, VS Code and the rest.

https://apis.io/mcp

Tools for apis

7 MCP tools reach this
  • find_apisBrowse and filter every API in the catalog.
  • get_api_artifactsOne API's artifacts, grouped by type.
  • get_openapiThe primary OpenAPI for this API.
  • find_similar_apisAPIs that look like this one.
  • apis_io_searchSTART HERE — APIs, providers and tags for one query, each with its total.
  • resolveTurn a domain, URL or GitHub org into the provider it belongs to.
  • find_cohortsEvery scored population of providers in the catalog.
All 92 tools →

Call it yourself

curl for this page
This API
curl "https://apis.io/api/v1/apis/twilio-auth-tokens-api"
All apis
curl "https://apis.io/api/v1/apis?limit=25"

Discovery needs no key. Ratings and market analysis are Pro.

Get an API key

Free tier, no form to fill in. Signing in shares your email address with us — we store it to create your key and to recognise you if you sign in with another provider. See our Privacy Policy and Terms.

A second provider on the same verified email joins the account you already have.

OpenAPI Specification

twilio-auth-tokens-api-openapi.yml Raw ↑
openapi: 3.2.0
info:
  title: Twilio Accounts Auth Tokens API
  description: Manage Twilio accounts and subaccounts programmatically. Create and configure subaccounts, manage API credentials, promote auth tokens, and control account-level settings for identity and access management.
  version: '2.0'
  contact:
    name: Twilio Support
    url: https://support.twilio.com
    email: support@twilio.com
  license:
    name: Apache 2.0
    url: https://www.apache.org/licenses/LICENSE-2.0.html
  termsOfService: https://www.twilio.com/legal/tos
servers:
- url: https://api.twilio.com/2010-04-01
  description: Twilio REST API v1
- url: https://accounts.twilio.com/v1
  description: Twilio Accounts API v1
security:
- accountSid_authToken: []
tags:
- name: Auth Tokens
  description: Manage primary and secondary auth tokens
paths:
  /AuthTokens/Promote:
    post:
      operationId: promoteAuthToken
      summary: Twilio Promote Secondary Auth Token
      description: Promote the secondary auth token to primary. The old primary token will be invalidated immediately.
      tags:
      - Auth Tokens
      responses:
        '200':
          description: Auth token promoted
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/AuthTokenPromotion'
  /AuthTokens/Secondary:
    post:
      operationId: createSecondaryAuthToken
      summary: Twilio Create a Secondary Auth Token
      description: Create a secondary auth token for the account. Use this to rotate auth tokens without downtime.
      tags:
      - Auth Tokens
      responses:
        '201':
          description: Secondary auth token created
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/SecondaryAuthToken'
    delete:
      operationId: deleteSecondaryAuthToken
      summary: Twilio Delete the Secondary Auth Token
      tags:
      - Auth Tokens
      responses:
        '204':
          description: Secondary auth token deleted
  /v1/AuthTokens/Promote:
    servers:
    - url: https://accounts.twilio.com
    description: Auth Token promotion
    x-twilio:
      defaultOutputProperties:
      - account_sid
      - auth_token
      - date_created
      pathType: instance
      mountName: auth_token_promotion
    post:
      description: Promote the secondary Auth Token to primary. After promoting the new token, all requests to Twilio using your old primary Auth Token will result in an error.
      tags:
      - Auth Tokens
      responses:
        '200':
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/accounts.v1.auth_token_promotion'
          description: OK
      security:
      - accountSid_authToken: []
      operationId: UpdateAuthTokenPromotion
      x-maturity:
      - GA
      summary: Update auth token promotion
      x-summary-source: derived
  /v1/AuthTokens/Secondary:
    servers:
    - url: https://accounts.twilio.com
    description: Secondary Auth Token
    x-twilio:
      defaultOutputProperties:
      - account_sid
      - secondary_auth_token
      - date_created
      pathType: instance
      mountName: secondary_auth_token
    post:
      description: Create a new secondary Auth Token
      tags:
      - Auth Tokens
      responses:
        '201':
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/accounts.v1.secondary_auth_token'
          description: Created
      security:
      - accountSid_authToken: []
      operationId: CreateSecondaryAuthToken
      x-maturity:
      - GA
      summary: Create secondary auth token
      x-summary-source: derived
    delete:
      description: Delete the secondary Auth Token from your account
      tags:
      - Auth Tokens
      responses:
        '204':
          description: The resource was deleted successfully.
      security:
      - accountSid_authToken: []
      operationId: DeleteSecondaryAuthToken
      x-maturity:
      - GA
      summary: Delete secondary auth token
      x-summary-source: derived
components:
  schemas:
    AuthTokenPromotion:
      type: object
      properties:
        account_sid:
          type: string
          pattern: ^AC[0-9a-fA-F]{32}$
        auth_token:
          type: string
          description: The new primary auth token
        date_created:
          type: string
          format: date-time
        date_updated:
          type: string
          format: date-time
        url:
          type: string
          format: uri
    SecondaryAuthToken:
      type: object
      properties:
        account_sid:
          type: string
          pattern: ^AC[0-9a-fA-F]{32}$
        secondary_auth_token:
          type: string
          description: The secondary auth token
        date_created:
          type: string
          format: date-time
        date_updated:
          type: string
          format: date-time
        url:
          type: string
          format: uri
    accounts.v1.auth_token_promotion:
      type: object
      properties:
        account_sid:
          type:
          - string
          - 'null'
          minLength: 34
          maxLength: 34
          pattern: ^AC[0-9a-fA-F]{32}$
          description: The SID of the [Account](https://www.twilio.com/docs/iam/api/account) that the secondary Auth Token was created for.
        auth_token:
          type:
          - string
          - 'null'
          description: The promoted Auth Token that must be used to authenticate future API requests.
          x-twilio:
            pii:
              handling: sensitive
              deleteSla: 0
        date_created:
          type:
          - string
          - 'null'
          format: date-time
          description: The date and time in UTC when the resource was created specified in [ISO 8601](https://en.wikipedia.org/wiki/ISO_8601) format.
        date_updated:
          type:
          - string
          - 'null'
          format: date-time
          description: The date and time in GMT when the resource was last updated specified in [ISO 8601](https://en.wikipedia.org/wiki/ISO_8601) format.
        url:
          type:
          - string
          - 'null'
          format: uri
          description: The URI for this resource, relative to `https://accounts.twilio.com`
    accounts.v1.secondary_auth_token:
      type: object
      properties:
        account_sid:
          type:
          - string
          - 'null'
          minLength: 34
          maxLength: 34
          pattern: ^AC[0-9a-fA-F]{32}$
          description: The SID of the [Account](https://www.twilio.com/docs/iam/api/account) that the secondary Auth Token was created for.
        date_created:
          type:
          - string
          - 'null'
          format: date-time
          description: The date and time in UTC when the resource was created specified in [ISO 8601](https://en.wikipedia.org/wiki/ISO_8601) format.
        date_updated:
          type:
          - string
          - 'null'
          format: date-time
          description: The date and time in UTC when the resource was last updated specified in [ISO 8601](https://en.wikipedia.org/wiki/ISO_8601) format.
        secondary_auth_token:
          type:
          - string
          - 'null'
          description: The generated secondary Auth Token that can be used to authenticate future API requests.
          x-twilio:
            pii:
              handling: sensitive
              deleteSla: 0
        url:
          type:
          - string
          - 'null'
          format: uri
          description: The URI for this resource, relative to `https://accounts.twilio.com`
  securitySchemes:
    accountSid_authToken:
      type: http
      scheme: basic
      description: Use your Twilio Account SID as the username and Auth Token as the password for HTTP Basic authentication.
externalDocs:
  description: Twilio Accounts API Documentation
  url: https://www.twilio.com/docs/iam/api/account