API keys
Create, list, rename and revoke the API keys of a workspace.
Create an API key
Creates an API key and returns its secret.
/api-keysRequires a full API key. The secret in key is returned only in this response and when you regenerate the key, so store it securely right away. The key also works as an SMTP password. See Authentication for what each scope allows.
Body parameters
namestringrequiredProduction web app. Must be unique among the workspace’s keys.scopestringdefault: fullfull for access to every endpoint, or sending for the send endpoints only. Can’t be changed later.
sending_domain_idstringThe ID of a sending domain (dom_…) to restrict a sending key to. The key can then only send from addresses on that domain. Ignored for full keys.
Returns
Returns 201 with the API key object and its secret:
keystringsecret_. Use it as the Bearer token. It’s never shown again.curl -X POST https://api.emailit.com/v2/api-keys \
-H "Authorization: Bearer $EMAILIT_API_KEY" \
-H "Content-Type: application/json" \
-d '{
"name": "Production web app",
"scope": "sending",
"sending_domain_id": "dom_4K468YrjOkR1wwdhqiO0G9XEUey"
}'const apiKey = await emailit.apiKeys.create({
name: 'Production web app',
scope: 'sending',
sending_domain_id: 'dom_4K468YrjOkR1wwdhqiO0G9XEUey',
});api_key = client.api_keys.create({
"name": "Production web app",
"scope": "sending",
"sending_domain_id": "dom_4K468YrjOkR1wwdhqiO0G9XEUey",
}){
"object": "api_key",
"id": "key_4KEaYMnfrxQGkuB0svwiuyt0ZhB",
"name": "Production web app",
"scope": "sending",
"sending_domain_id": "dom_4K468YrjOkR1wwdhqiO0G9XEUey",
"last_used_at": null,
"created_at": "2026-10-01T09:40:18.204917Z",
"updated_at": "2026-10-01T09:40:18.204917Z",
"key": "secret_Xq7pL2mN9vB4kR8tW1yZ6cH3jF5dS0aG"
}{
"error": "Invalid sending_domain_id. Domain not found in workspace"
}{
"error": "API key with this name already exists",
"existing": {
"object": "api_key",
"id": "key_4Kw6E8FodRivXbJlwPdn79gOxi1",
"name": "Production web app"
}
}Retrieve an API key
Retrieves an API key’s details. The secret isn’t included.
/api-keys/{id}Requires a full API key. Deleted keys aren’t found.
Path parameters
idstringrequiredkey_…) or its name. URL-encode names with spaces.Returns
Returns the API key object.
objectstringapi_key.idstringnamestringscopestringfull or sending.sending_domain_idstring | nullnull.last_used_atstring | nullnull if it hasn’t been used since it was created or regenerated.created_atstringupdated_atstring{
"object": "api_key",
"id": "key_4KEaYMnfrxQGkuB0svwiuyt0ZhB",
"name": "Production web app",
"scope": "sending",
"sending_domain_id": "dom_4K468YrjOkR1wwdhqiO0G9XEUey",
"last_used_at": "2026-10-01T11:58:02.000000Z",
"created_at": "2026-10-01T09:40:18.204917Z",
"updated_at": "2026-10-01T09:40:18.204917Z"
}{
"error": "API key not found"
}List API keys
Returns a page of the workspace’s API keys, newest first.
/api-keysRequires a full API key. Deleted keys and secrets aren’t included. Check last_used_at to find keys you no longer use.
Query parameters
pageintegerdefault: 1limitintegerdefault: 10searchstringmatchstringdefault: allall or or. How the filters below combine.orderstringdirectionstringasc or desc.Filters
Add filters as key.condition=value, for example scope.exact=sending. See Filtering.
| Key | Type | Notes |
|---|---|---|
name |
string | |
scope |
string | full or sending. |
type |
string | Credential type. Keys created in the dashboard or API are api. |
created_at |
date |
Every key is also a sort key.
Returns
Returns a data array of API key objects with next_page_url and previous_page_url. See Pagination.
{
"data": [
{
"object": "api_key",
"id": "key_4KEaYMnfrxQGkuB0svwiuyt0ZhB",
"name": "Production web app",
"scope": "sending",
"sending_domain_id": "dom_4K468YrjOkR1wwdhqiO0G9XEUey",
"last_used_at": "2026-10-01T11:58:02.000000Z",
"created_at": "2026-10-01T09:40:18.204917Z",
"updated_at": "2026-10-01T09:40:18.204917Z"
},
{
"object": "api_key",
"id": "key_4Kw6E8FodRivXbJlwPdn79gOxi1",
"name": "Back office",
"scope": "full",
"sending_domain_id": null,
"last_used_at": null,
"created_at": "2026-09-02T14:21:07.613508Z",
"updated_at": "2026-09-02T14:21:07.613508Z"
}
],
"next_page_url": null,
"previous_page_url": null
}Update an API key
Renames an API key.
/api-keys/{id}Requires a full API key. Only the name can change. To change the scope or domain restriction, create a new key and delete this one. To replace the secret, regenerate it.
Path parameters
idstringrequiredBody parameters
namestringrequiredReturns
Returns the updated API key object.
{
"object": "api_key",
"id": "key_4KEaYMnfrxQGkuB0svwiuyt0ZhB",
"name": "Production web app (EU)",
"scope": "sending",
"sending_domain_id": "dom_4K468YrjOkR1wwdhqiO0G9XEUey",
"last_used_at": "2026-10-01T11:58:02.000000Z",
"created_at": "2026-10-01T09:40:18.204917Z",
"updated_at": "2026-10-01T12:10:33.000000Z"
}{
"error": "API key not found"
}{
"error": "Another API key with this name already exists"
}Regenerate an API key
Replaces the key’s secret with a new one. The previous secret stops working immediately for API requests and new SMTP logins. The key keeps its ID, name, scope and sending domain, and last_used_at is reset. Requires an API key with the full scope.
The new secret is returned only in this response. Store it right away, then update every app and SMTP client that used the old one. If you regenerate the key that makes this request, use the new secret for later requests.
/api-keys/{id}/regeneratePath parameters
idstringrequiredkey_…) or the key’s name.Returns
Returns the API key object with the new secret in key.
keystringsecret_ followed by 32 letters and digits. Shown only once.scopestringfull or sending.sending_domain_idstring | nullsending key is limited to, or null.last_used_atnullnull after a regeneration.Returns 404 if no active API key matches id.
{
"object": "api_key",
"id": "key_3t4p05pmtgBssZzXRT0QmJn3UgH",
"name": "Production server",
"key": "secret_tbgPKVFk7QMi1nneTKdFcUWTyh8XoPz3",
"scope": "sending",
"sending_domain_id": "dom_3bTLTaNUAcCiXuokxifeIYdFOYf",
"last_used_at": null,
"created_at": "2026-09-12 08:01:44.120931+00",
"updated_at": "2026-10-01T13:15:07.402881Z"
}{
"error": "API key not found"
}Delete an API key
Revokes an API key. Requests and SMTP logins with its secret fail from now on.
/api-keys/{id}Requires a full API key. You can delete the key you’re calling with, so make sure your integration has another key first. A deleted key no longer appears in List API keys, and its name becomes free for a new key. Emails already sent with the key are unaffected.
Path parameters
idstringrequiredReturns
objectstringapi_key.idstringnamestringdeletedbooleantrue.{
"object": "api_key",
"id": "key_4Kw6E8FodRivXbJlwPdn79gOxi1",
"name": "Back office",
"deleted": true
}{
"error": "API key not found"
}