Skip to content
Docs

Create, list, rename and revoke the API keys of a workspace.

Base URLhttps://api.emailit.com/v2AuthenticationErrorsRate limits

Create an API key

Creates an API key and returns its secret.

POST/api-keys

Requires a full API key. The secret in key is returned only in this response and when you regenerate the key, so store it securely right away. The key also works as an SMTP password. See Authentication for what each scope allows.

Body parameters

namestringrequired
A name that tells you where the key is used, such as Production web app. Must be unique among the workspace’s keys.
scopestringdefault: full

full for access to every endpoint, or sending for the send endpoints only. Can’t be changed later.

sending_domain_idstring

The ID of a sending domain (dom_…) to restrict a sending key to. The key can then only send from addresses on that domain. Ignored for full keys.

Returns

Returns 201 with the API key object and its secret:

keystring
The secret, starting with secret_. Use it as the Bearer token. It’s never shown again.
POST/api-keys
Terminal
curl -X POST https://api.emailit.com/v2/api-keys \
  -H "Authorization: Bearer $EMAILIT_API_KEY" \
  -H "Content-Type: application/json" \
  -d '{
    "name": "Production web app",
    "scope": "sending"
  }'
Terminal
curl -X POST https://api.emailit.com/v2/api-keys \
  -H "Authorization: Bearer $EMAILIT_API_KEY" \
  -H "Content-Type: application/json" \
  -d '{
    "name": "Production web app",
    "scope": "sending",
    "sending_domain_id": "dom_4K468YrjOkR1wwdhqiO0G9XEUey"
  }'
JSON
{
  "object": "api_key",
  "id": "key_4KEaYMnfrxQGkuB0svwiuyt0ZhB",
  "name": "Production web app",
  "scope": "sending",
  "sending_domain_id": "dom_4K468YrjOkR1wwdhqiO0G9XEUey",
  "last_used_at": null,
  "created_at": "2026-10-01T09:40:18.204917Z",
  "updated_at": "2026-10-01T09:40:18.204917Z",
  "key": "secret_Xq7pL2mN9vB4kR8tW1yZ6cH3jF5dS0aG"
}

Retrieve an API key

Retrieves an API key’s details. The secret isn’t included.

GET/api-keys/{id}

Requires a full API key. Deleted keys aren’t found.

Path parameters

idstringrequired
The API key ID (key_…) or its name. URL-encode names with spaces.

Returns

Returns the API key object.

objectstring
Always api_key.
idstring
The API key ID.
namestring
The key’s name.
scopestring
full or sending.
sending_domain_idstring | null
The ID of the sending domain the key is restricted to, or null.
last_used_atstring | null
When the key last authenticated a request, or null if it hasn’t been used since it was created or regenerated.
created_atstring
When the key was created.
updated_atstring
When the key was last renamed or regenerated.
GET/api-keys/{id}
Terminal
curl https://api.emailit.com/v2/api-keys/key_4KEaYMnfrxQGkuB0svwiuyt0ZhB \
  -H "Authorization: Bearer $EMAILIT_API_KEY"
JSON
{
  "object": "api_key",
  "id": "key_4KEaYMnfrxQGkuB0svwiuyt0ZhB",
  "name": "Production web app",
  "scope": "sending",
  "sending_domain_id": "dom_4K468YrjOkR1wwdhqiO0G9XEUey",
  "last_used_at": "2026-10-01T11:58:02.000000Z",
  "created_at": "2026-10-01T09:40:18.204917Z",
  "updated_at": "2026-10-01T09:40:18.204917Z"
}

List API keys

Returns a page of the workspace’s API keys, newest first.

GET/api-keys

Requires a full API key. Deleted keys and secrets aren’t included. Check last_used_at to find keys you no longer use.

Query parameters

pageintegerdefault: 1
The page to return.
limitintegerdefault: 10
Keys per page, from 1 to 100.
matchstringdefault: all
all or or. How the filters below combine.
orderstring
A filter key to sort by.
directionstring
asc or desc.

Filters

Add filters as key.condition=value, for example scope.exact=sending. See Filtering.

Key Type Notes
name string
scope string full or sending.
type string Credential type. Keys created in the dashboard or API are api.
created_at date

Every key is also a sort key.

Returns

Returns a data array of API key objects with next_page_url and previous_page_url. See Pagination.

GET/api-keys
Terminal
curl https://api.emailit.com/v2/api-keys \
  -H "Authorization: Bearer $EMAILIT_API_KEY"
JSON
{
  "data": [
    {
      "object": "api_key",
      "id": "key_4KEaYMnfrxQGkuB0svwiuyt0ZhB",
      "name": "Production web app",
      "scope": "sending",
      "sending_domain_id": "dom_4K468YrjOkR1wwdhqiO0G9XEUey",
      "last_used_at": "2026-10-01T11:58:02.000000Z",
      "created_at": "2026-10-01T09:40:18.204917Z",
      "updated_at": "2026-10-01T09:40:18.204917Z"
    },
    {
      "object": "api_key",
      "id": "key_4Kw6E8FodRivXbJlwPdn79gOxi1",
      "name": "Back office",
      "scope": "full",
      "sending_domain_id": null,
      "last_used_at": null,
      "created_at": "2026-09-02T14:21:07.613508Z",
      "updated_at": "2026-09-02T14:21:07.613508Z"
    }
  ],
  "next_page_url": null,
  "previous_page_url": null
}

Update an API key

Renames an API key.

POST/api-keys/{id}

Requires a full API key. Only the name can change. To change the scope or domain restriction, create a new key and delete this one. To replace the secret, regenerate it.

Path parameters

idstringrequired
The API key ID or its current name.

Body parameters

namestringrequired
The new name. Must be unique among the workspace’s keys.

Returns

Returns the updated API key object.

POST/api-keys/{id}
Terminal
curl -X POST https://api.emailit.com/v2/api-keys/key_4KEaYMnfrxQGkuB0svwiuyt0ZhB \
  -H "Authorization: Bearer $EMAILIT_API_KEY" \
  -H "Content-Type: application/json" \
  -d '{
    "name": "Production web app (EU)"
  }'
JSON
{
  "object": "api_key",
  "id": "key_4KEaYMnfrxQGkuB0svwiuyt0ZhB",
  "name": "Production web app (EU)",
  "scope": "sending",
  "sending_domain_id": "dom_4K468YrjOkR1wwdhqiO0G9XEUey",
  "last_used_at": "2026-10-01T11:58:02.000000Z",
  "created_at": "2026-10-01T09:40:18.204917Z",
  "updated_at": "2026-10-01T12:10:33.000000Z"
}

Regenerate an API key

Replaces the key’s secret with a new one. The previous secret stops working immediately for API requests and new SMTP logins. The key keeps its ID, name, scope and sending domain, and last_used_at is reset. Requires an API key with the full scope.

The new secret is returned only in this response. Store it right away, then update every app and SMTP client that used the old one. If you regenerate the key that makes this request, use the new secret for later requests.

POST/api-keys/{id}/regenerate

Path parameters

idstringrequired
The API key ID (key_…) or the key’s name.

Returns

Returns the API key object with the new secret in key.

keystring
The new secret, secret_ followed by 32 letters and digits. Shown only once.
scopestring
full or sending.
sending_domain_idstring | null
The sending domain a sending key is limited to, or null.
last_used_atnull
Always null after a regeneration.

Returns 404 if no active API key matches id.

POST/api-keys/{id}/regenerate
Terminal
curl -X POST https://api.emailit.com/v2/api-keys/key_3t4p05pmtgBssZzXRT0QmJn3UgH/regenerate \
  -H "Authorization: Bearer $EMAILIT_API_KEY"
JSON
{
  "object": "api_key",
  "id": "key_3t4p05pmtgBssZzXRT0QmJn3UgH",
  "name": "Production server",
  "key": "secret_tbgPKVFk7QMi1nneTKdFcUWTyh8XoPz3",
  "scope": "sending",
  "sending_domain_id": "dom_3bTLTaNUAcCiXuokxifeIYdFOYf",
  "last_used_at": null,
  "created_at": "2026-09-12 08:01:44.120931+00",
  "updated_at": "2026-10-01T13:15:07.402881Z"
}

Delete an API key

Revokes an API key. Requests and SMTP logins with its secret fail from now on.

DELETE/api-keys/{id}

Requires a full API key. You can delete the key you’re calling with, so make sure your integration has another key first. A deleted key no longer appears in List API keys, and its name becomes free for a new key. Emails already sent with the key are unaffected.

Path parameters

idstringrequired
The API key ID or its name.

Returns

objectstring
Always api_key.
idstring
The ID of the deleted key.
namestring
The key’s name.
deletedboolean
Always true.
DELETE/api-keys/{id}
Terminal
curl -X DELETE https://api.emailit.com/v2/api-keys/key_4Kw6E8FodRivXbJlwPdn79gOxi1 \
  -H "Authorization: Bearer $EMAILIT_API_KEY"
JSON
{
  "object": "api_key",
  "id": "key_4Kw6E8FodRivXbJlwPdn79gOxi1",
  "name": "Back office",
  "deleted": true
}

Was this page helpful?

Thanks for the feedback.

Thanks, we read every message.