Skip to main content
🤖 LLM Friendly: This page is available in raw Markdown format for LLM consumption:push-credentials.md|Get full documentation:llms.txt/llms-full.txt

Push Credentials

Configure push notification credentials for your custom mobile applications to receive VoIP push notifications when incoming calls arrive. Each credential is tied to an API Key SID and enables Firetell to dispatch push notifications using your own APNs (iOS) or FCM (Android) credentials instead of Firetell's built-in push infrastructure.

info

When to Use Push Credentials

Push credentials are required when you build your own mobile app (not the Firetell Agent app) and want to receive incoming call pushes. If your agents use the official Firetell Agent app, push credentials are already configured — you do not need to set up anything here.

Endpoints​

MethodEndpointDescription
GET/push-credentialsList all push credentials
GET/push-credentials/:idGet push credential details
POST/push-credentialsCreate a new push credential
PATCH/push-credentials/:idUpdate a push credential
DELETE/push-credentials/:idDelete a push credential

The Push Credential Object​

FieldTypeDescription
idstringUnique identifier (prefixed with pc_)
workspace_idstringWorkspace identifier
api_key_sidstringThe API Key SID that this credential is associated with
namestringDisplay name for this credential
platformstringPlatform: ios or android
enabledbooleanWhether this credential is active
apns_key_idstring(iOS only) 10-character Key ID from Apple Developer portal
apns_team_idstring(iOS only) 10-character Team ID from Apple Developer portal
apns_private_key_encryptedstring(iOS only) Always "******" in responses — the private key is encrypted at rest
apns_bundle_idstring(iOS only) iOS app bundle identifier (e.g., com.yourcompany.app)
apns_environmentstring(iOS only) sandbox or production
fcm_service_account_encryptedstring(Android only) Always "******" in responses — the service account is encrypted at rest
fcm_package_namestring(Android only) Android app package name
created_atstringISO 8601 creation timestamp
updated_atstringISO 8601 last update timestamp
caution

Credential Security

Sensitive fields (apns_private_key, fcm_service_account) are encrypted at rest using AES-256-GCM and are never returned in API responses. You will see "******" as a placeholder. If you lose your credentials, you must re-upload new ones.


Quota​

Each workspace can have a maximum of 30 push credentials. If you need more, contact enterprise@firetell.com.


List Push Credentials​

GET /push-credentials

Retrieve a paginated list of all push credentials in the workspace.

Authentication​

Requires ApiKey or JWT with any role.

Query Parameters​

ParameterTypeDefaultDescription
pagenumber1Page number (min: 1)
limitnumber20Items per page (min: 1, max: 100)

Request​

curl -X GET "https://{workspace_id}.firetell.app/api/v1/push-credentials?page=1&limit=10" \
-H "Authorization: ApiKey sk-YOUR_API_KEY"

Response​

{
"data": [
{
"id": "pc_a1b2c3d4e5f6g7h8",
"workspace_id": "ws_123456789",
"api_key_sid": "sid-650000000000000000000001",
"name": "Production iOS App",
"platform": "ios",
"enabled": true,
"apns_key_id": "ABC123DEFG",
"apns_team_id": "TEAM123456",
"apns_private_key_encrypted": "******",
"apns_bundle_id": "com.yourcompany.app",
"apns_environment": "production",
"created_at": "2026-08-01T10:00:00.000Z",
"updated_at": "2026-08-01T10:00:00.000Z"
}
],
"meta": {
"total": 1,
"page": 1,
"limit": 20,
"total_pages": 1
}
}

Get Push Credential​

GET /push-credentials/:id

Retrieve the details of a specific push credential.

Authentication​

Requires ApiKey or JWT with any role.

Request​

curl -X GET "https://{workspace_id}.firetell.app/api/v1/push-credentials/pc_a1b2c3d4e5f6g7h8" \
-H "Authorization: ApiKey sk-YOUR_API_KEY"

Response​

{
"id": "pc_a1b2c3d4e5f6g7h8",
"workspace_id": "ws_123456789",
"api_key_sid": "sid-650000000000000000000001",
"name": "Production iOS App",
"platform": "ios",
"enabled": true,
"apns_key_id": "ABC123DEFG",
"apns_team_id": "TEAM123456",
"apns_private_key_encrypted": "******",
"apns_bundle_id": "com.yourcompany.app",
"apns_environment": "production",
"created_at": "2026-08-01T10:00:00.000Z",
"updated_at": "2026-08-01T10:00:00.000Z"
}

Create Push Credential​

POST /push-credentials

Create a new push credential. The request body varies depending on the platform.

Authentication​

Requires ApiKey or JWT with role owner or editor.

Request Body (iOS / APNs)​

ParameterTypeRequiredDescription
namestringYesDisplay name (max 100 chars)
api_key_sidstringYesAPI Key SID (sid-...) to associate this credential with
platformstringYesMust be ios
apns_key_idstringYes10-character Key ID from Apple Developer portal
apns_team_idstringYes10-character Team ID from Apple Developer portal
apns_private_keystringYesFull content of the .p8 private key file (PEM format)
apns_bundle_idstringYesiOS app bundle identifier (e.g., com.yourcompany.app)
apns_environmentstringNosandbox (default) or production

Request Example (iOS)​

curl -X POST "https://{workspace_id}.firetell.app/api/v1/push-credentials" \
-H "Authorization: ApiKey sk-YOUR_API_KEY" \
-H "Content-Type: application/json" \
-d '{
"name": "Production iOS App",
"api_key_sid": "sid-650000000000000000000001",
"platform": "ios",
"apns_key_id": "ABC123DEFG",
"apns_team_id": "TEAM123456",
"apns_private_key": "-----BEGIN PRIVATE KEY-----\nMIGHAgEAMBMGByqGSM49AgEGCC...\n-----END PRIVATE KEY-----",
"apns_bundle_id": "com.yourcompany.app",
"apns_environment": "production"
}'

Request Body (Android / FCM)​

ParameterTypeRequiredDescription
namestringYesDisplay name (max 100 chars)
api_key_sidstringYesAPI Key SID (sid-...) to associate this credential with
platformstringYesMust be android
fcm_service_accountstringYesFirebase Service Account JSON (must have "type": "service_account")
fcm_package_namestringNoAndroid package name (e.g., com.yourcompany.app)

Request Example (Android)​

curl -X POST "https://{workspace_id}.firetell.app/api/v1/push-credentials" \
-H "Authorization: ApiKey sk-YOUR_API_KEY" \
-H "Content-Type: application/json" \
-d '{
"name": "Production Android App",
"api_key_sid": "sid-650000000000000000000001",
"platform": "android",
"fcm_service_account": "{\"type\": \"service_account\", \"project_id\": \"my-project\", ...}",
"fcm_package_name": "com.yourcompany.app"
}'

Response (201 Created)​

{
"id": "pc_a1b2c3d4e5f6g7h8",
"workspace_id": "ws_123456789",
"api_key_sid": "sid-650000000000000000000001",
"name": "Production iOS App",
"platform": "ios",
"enabled": true,
"apns_key_id": "ABC123DEFG",
"apns_team_id": "TEAM123456",
"apns_private_key_encrypted": "******",
"apns_bundle_id": "com.yourcompany.app",
"apns_environment": "production",
"created_at": "2026-08-01T10:00:00.000Z",
"updated_at": "2026-08-01T10:00:00.000Z"
}

Update Push Credential​

PATCH /push-credentials/:id

Update an existing push credential. Only the fields you provide will be updated.

Authentication​

Requires ApiKey or JWT with role owner or editor.

Request Body​

ParameterTypeDescription
namestringUpdated display name
enabledbooleanEnable or disable this credential
apns_key_idstring(iOS) Updated Key ID
apns_team_idstring(iOS) Updated Team ID
apns_private_keystring(iOS) New private key (replaces existing)
apns_bundle_idstring(iOS) Updated bundle identifier
apns_environmentstring(iOS) sandbox or production
fcm_service_accountstring(Android) New service account JSON (replaces existing)
fcm_package_namestring(Android) Updated package name
tip

To rotate credentials, only send the apns_private_key or fcm_service_account field. Other fields remain unchanged.

Request​

curl -X PATCH "https://{workspace_id}.firetell.app/api/v1/push-credentials/pc_a1b2c3d4e5f6g7h8" \
-H "Authorization: ApiKey sk-YOUR_API_KEY" \
-H "Content-Type: application/json" \
-d '{
"name": "Updated iOS App Name",
"apns_environment": "production"
}'

Response​

{
"id": "pc_a1b2c3d4e5f6g7h8",
"workspace_id": "ws_123456789",
"api_key_sid": "sid-650000000000000000000001",
"name": "Updated iOS App Name",
"platform": "ios",
"enabled": true,
"apns_key_id": "ABC123DEFG",
"apns_team_id": "TEAM123456",
"apns_private_key_encrypted": "******",
"apns_bundle_id": "com.yourcompany.app",
"apns_environment": "production",
"created_at": "2026-08-01T10:00:00.000Z",
"updated_at": "2026-08-05T14:30:00.000Z"
}

Delete Push Credential​

DELETE /push-credentials/:id

Permanently delete a push credential. Devices associated with the API Key SID will no longer receive VoIP push notifications.

Authentication​

Requires ApiKey or JWT with role owner or editor.

Request​

curl -X DELETE "https://{workspace_id}.firetell.app/api/v1/push-credentials/pc_a1b2c3d4e5f6g7h8" \
-H "Authorization: ApiKey sk-YOUR_API_KEY"

Response​

{
"deleted": true
}

Error Responses​

Quota Exceeded (403)​

{
"statusCode": 403,
"message": "Maximum 30 push credentials per workspace. Delete unused credentials first.",
"error": "Forbidden"
}

Invalid API Key SID (400)​

{
"statusCode": 400,
"message": "API Key with SID \"sid-invalid\" not found in this workspace.",
"error": "Bad Request"
}

Invalid FCM Service Account (400)​

{
"statusCode": 400,
"message": "fcm_service_account must be a valid Firebase Service Account JSON with \"type\": \"service_account\".",
"error": "Bad Request"
}