Before the first request
- Store
SENDORA_API_KEYin a secret manager or environment variable. - Use a deliberately isolated workspace for development. A
sk_test_key is not automatically isolated from real data, sends, calls, or charges. - Start with
GETrequests and confirm the workspace and resource IDs in the response. - Treat IDs as opaque strings; never derive or expose internal database identifiers.
Before every write
- Confirm the target workspace, resource, and intended side effect.
- Use an idempotency key when the endpoint documents one.
- Use preview endpoints before prospecting or bulk mutations.
- Use draft and preflight states before publishing or launching campaigns and voice agents.
- Keep bulk operations bounded and persist returned job or preview IDs.
Never automate blindly
Do not automatically retry a request that can send a message, start a call, launch a campaign, publish an experience, change a plan, rotate a secret, or delete data. After a timeout, inspect the resource, job, or delivery history first.Production readiness
- Handle
401,403,404,409,422, and429explicitly. - Retry only transient
429and5xxresponses with exponential backoff and jitter. - Verify webhook signatures using the raw request body before parsing it.
- Deduplicate webhook deliveries and make consumers safe for at-least-once delivery.
- Log request IDs, operation IDs, resource IDs, and job IDs without logging API keys or webhook secrets.
- Keep a tested key-rotation procedure for every integration.