Docs
Developer CenterDashboardesimoa.com
    • Introduction
    • Quickstart
    • Authentication
    • Overview
    • List eSIMs
    • Get an eSIM
    • Countries
    • OpenAPI
    • Tracking & commission
    • Rate limits & errors
    • Overview
    • Claude
    • ChatGPT
    • Gemini
    • Other MCP clients
    • Overview
    • Authentication
    • Products
    • Product detail
    • Countries
    • Errors & rate limits
  1. Docs
  2. Partner API (B2B)
  3. Authentication

Partner API (B2B)

Authentication

Authenticate with an API key from the partner portal, and rotate, restrict or revoke keys.

On this page
  • Key format
  • Sending the key
  • Issuing keys
  • Rotating keys
  • IP allowlist
  • Revoking keys
  • Member roles

Key format#

text
esk_live_<prefix:10>_<secret:40>

A key is an alphanumeric string made of a 10-character prefix (a public identifier shown in the portal) and a 40-character secret. esimoa stores only a SHA-256 hash, so the full key is shown once at issue time and cannot be recovered.

Note

This differs from Developer Center Public API keys (esk_live_<32>). Using one in the other API is rejected with INVALID_API_KEY.

Sending the key#

Send the key in the X-API-Key header on every request; Authorization: Bearer is also accepted. No key returns 401 API_KEY_REQUIRED, and a malformed or unknown key returns 401 INVALID_API_KEY.

http
# Preferred
X-API-Key: esk_live_AbCdE12345_<40-character secret>

# Also accepted
Authorization: Bearer esk_live_AbCdE12345_<40-character secret>

Issuing keys#

  1. 1Partner portal → API keys — create a new key.
  2. 2Give it a name and, optionally, an expiry (between 1 minute and 3 years from now) and an IP allowlist.
  3. 3Copy the key right away — it is displayed only once — and store it in a secret manager or a server environment variable.

Each account can have up to 5 active keys by default (keys that are neither revoked nor expired).

Rotating keys#

Rotating creates a new key with the same name, scopes, IP allowlist and expiry. The old key keeps working for the grace period you choose (0–72 hours) and then expires — deploy the new key within that window. A grace period of 0 cuts the old key off immediately.

Note

Revoked or already-expired keys cannot be rotated — issue a new key instead. Once the grace period ends, the old key gets 401 KEY_EXPIRED.

IP allowlist#

Each key can be limited to up to 20 IPv4/IPv6 addresses or CIDR ranges (e.g. 203.0.113.10, 198.51.100.0/24). An empty list means no restriction; requests from elsewhere get 403 IP_NOT_ALLOWED. Use your servers’ egress IPs.

Revoking keys#

Revoke a key in the portal as soon as it leaks or is no longer needed. Keys are not cached, so the very next request is rejected with 401 KEY_REVOKED. In an emergency esimoa can revoke keys or suspend an account; every key of a suspended account gets 403 PARTNER_SUSPENDED.

Member roles#

RoleCan do
OWNEREverything
ADMINManage keys and members
DEVELOPERManage keys, browse products
VIEWERRead only

Only OWNER, ADMIN and DEVELOPER members can issue, rotate or revoke keys; every member can see the key list.

Last updated: October 1, 2026

PreviousPartner API (B2B)NextProducts

On this page

  • Key format
  • Sending the key
  • Issuing keys
  • Rotating keys
  • IP allowlist
  • Revoking keys
  • Member roles

APIs and MCP for bringing esimoa eSIMs to your product

Resources

  • Docs
  • API reference
  • Partner API (B2B)
  • MCP server
  • OpenAPI spec

esimoa

  • Home
  • eSIM plans
  • Developer Center
  • Dashboard
  • Partner portal

Company

  • About Us
  • Partnership
  • Terms of Service
  • Privacy Policy
  • Delivery & Refunds Policy

Support

  • support@esimoa.com
  • Support chat

NBase Korea Co., Ltd.

902, Bldg A, 767 Sinsu-ro, Suji-gu, Yongin-si, Gyeonggi-do (Dongcheon-dong, Bundang Suji U-TOWER)

US Headquarters: NBASE CORP. · Corporate Park, Irvine, CA 92606, USA

© 2026 esimoa. All rights reserved.