Skip to main content
At the end you will have one client application for a test merchant, a test code delivered to your phone and checked, and your webhook receiving the signed event. Nothing here needs Tawked’s approval: the sandbox key sends while the application is still in review.

Hand this to your coding agent to wire the Tawked Partner API into your platform.

Open in Cursor
Before you start
  • A partner account. Tawked opens them: write to support@tawked.com.
  • Access to Clients with manage rights. The owner always has it.
  • The phone the account owner verified at signup, in your hand: test codes reach only that number.
1

Create your two keys

In the console, open Clients → API and webhook.
  • Partner key, Create the key: the live tk_partner_ key. It provisions and changes applications, and sends real codes.
  • Sandbox key, Create a sandbox key: the tk_partner_test_ key. It reads everything and sends to the owner’s phone only, with the [TEST] stamp. It changes nothing.
Each key is shown once. Put them in your server’s environment:
.env
2

Point the webhook at your server

Still on Clients → API and webhook, Webhook, Add the URL: an https:// address on a public host. Keep the Signing secret beside your keys.Then subscribe to the code outcomes as well as the defaults, so the test in step 5 reaches you:
The answer is the configuration, with events as you set them. Partner events lists every event and the defaults.
3

Provision a test merchant

Create the application with the live key, with your own id for the merchant as external_id:
201 Created
status is review while a decision is pending, or active at once under the auto-clean approval mode. screening.rules lists what the names tripped, if anything. A second call with the same external_id answers 200 with the application as it stands, so a retry never makes two.Likely errors: 400 invalid_request with fields naming what was refused, and 403 live_key_required if you used the sandbox key.
4

Send a test code to your phone

Now the sandbox key, with application naming the merchant and to the owner’s verified phone:
201 Created
The SMS goes out under Tawked’s sender ID with the [TEST] stamp. It names the merchant’s application when screening found its names clean, and a neutral test name otherwise. The sandbox key sends 20 codes per application and 200 per account a day (Riyadh time), each charged like a live send.Likely errors: 422 sandbox_unverified_destination for any other number, 429 sandbox_quota_exceeded past the daily caps, and 404 service_not_found for an external_id you have not provisioned.
5

Check the code

Send the code you received, with the same application:
200 OK
A wrong code answers "verified": false with status: "invalid_code" and attempts_remaining. Branch on verified.
6

Receive the webhook

The check fires verification.verified to your webhook, with mode: "partner_test" and your external_id in data:
Verify tawked-signature against the raw body with your signing secret; the code is on Webhooks. Answer 2xx within 5 seconds. Delivery log on Clients → API and webhook shows the attempt and your server’s answer.If you do not want one event per code in production, drop verification.verified from events later.

Go live

  1. Wait for the decision. service.approved reaches your webhook when the application is approved, by you in Clients → Reviews or by Tawked, according to your approval mode. GET /v1/partner/profile says which mode you have. service.rejected carries a reason_code; fix the brand and PATCH it to resubmit.
  2. Send with the live key. Swap TAWKED_PARTNER_TEST_KEY for TAWKED_PARTNER_KEY in the Verify calls. Codes then reach any Saudi mobile and are charged to your balance at your price.
  3. Keep the balance up. A send with an empty balance answers 402 insufficient_credits. balance.low warns you first; set its threshold on Clients → API and webhook, Webhook.
  4. Pass client_ip and an Idempotency-Key on every start, so the per-address cap and safe retries protect you. See Reliability and limits.

Applications

Bulk provisioning, brand updates, verify settings, suspend and archive.

Sending codes for an application

What blocks a send, the code log and the sandbox key in full.

Events

Every event, the rejection codes, and the feed to poll.

Errors

Every code, what to do and whether to retry.
Last modified on October 6, 2026