Workspace, billing & integrations5 steps

API keys and the REST API

Create keys, then read your data and create campaigns, add leads and reply to leads from your own tools (a two-way REST API).

Where: Settings → API & webhooks → API (top of the page). Base URL https://mailfleet.co/api/v1.

How to do it

  1. Open Settings → API & webhooks and click Create API key.
  2. Enter a Key name (up to 60 characters, e.g. "HubSpot sync"), choose its Access — Read & write (read everything and make changes) or Read only (for dashboards and reports) — and click Create key.
  3. Copy the key from the "Copy your new key now — it won't be shown again" box (Copy key), then click Done.
  4. Call the API with the header Authorization: Bearer sk_live_… (or X-API-Key: sk_live_…). The Quickstart section has a ready-made curl command (Copy curl), the Full reference ↗ and the OpenAPI spec ↗.
  5. Manage keys in Your keys (Name, Key — the first characters only — Access, Last used, Created); click the trash icon to Revoke a key.

Good to know

  • Keys start with sk_live_ and are shown once; only a hash is stored. Keep a key secret: a Read & write key can make changes in your workspace and email your leads.
  • Keys created before the API could make changes (September 29, 2026) are Read only. A change sent with a read-only key is answered 403 with the code read_only_key — create a new Read & write key for it.
  • Reading (GET): campaigns (with their stats, schedule, senders and step count), a campaign's steps, senders, schedule and leads (where each is in the sequence), leads (filter by status, search, email or list_id) and one lead with its custom fields and campaigns, lists, replies (filter by intent, campaign_id, lead_id, handled, received_after) and one whole conversation, senders, the blocklist, webhooks, and stats.
  • Changing (needs a Read & write key): create, rename and delete campaigns; replace a campaign's sequence (email, manual and call steps with A/B variants); set its senders and schedule; start, resume and pause it (with the same checks as Launch in the app); add leads to a campaign (up to 2,000 per call — only the people sent are enrolled) or enrol a whole list; remove a lead from a campaign; add and update leads (and their custom fields); unsubscribe a lead; create lists; reply to a lead; mark a conversation (Mark lead as: Interested, Meeting booked, Won …, handled, read, tags); add to the blocklist; create and delete webhooks.
  • Every change runs the same code as the app, so it behaves exactly as doing it in MailFleet: imports dedupe by email and respect the blocklist and your room for leads; a reply goes from the mailbox the lead wrote to, even if it's paused, and the same reply can't go twice within a minute.
  • Send an Idempotency-Key header (a UUID) with a request that creates or sends something: if you retry it with the same key and body, you get the first response back instead of it happening twice. Keys last 24 hours.
  • Campaign stats (on GET /campaigns and /campaigns/{id}) count the way a campaign's Analytics does: sent, delivered, bounced and blocked are emails — bounced is the hard bounces (a bad address, the same as hard_bounced) and blocked is emails refused as spam, never added into bounced; opened, clicked, replied and interested are people, out of leads_reached (people with at least one delivered email). Every recorded open counts; clicks in the first 5 minutes after sending, and out-of-office and auto-replies, are left out. GET /stats adds them up across campaigns (emails.delivered_all_time, engagement.hard_bounced, blocked and leads_reached).
  • List endpoints accept limit (1–100, default 25) and offset (default 0) and return { object: "list", data, pagination: { total, limit, offset, has_more } }. Field names are snake_case (first_name, sent_today, daily_limit…). Errors are { error: { code, message, param } } — param names the field that failed.
  • Rate limit: 120 requests per minute per key (HTTP 429 when exceeded). Repeated invalid keys are throttled per IP.
  • API access is a Pro and Scale feature. You can create a key on any plan, but requests from a Trial or Basic workspace return 403 with the message "The MailFleet API is available on the Pro and Scale plans."
  • GET /api/v1 (no key needed) lists every endpoint; the full reference is at mailfleet.co/docs/api.
  • A key named "Zapmail" in your list was created by logging in through Zapmail (see the Zapmail article); revoke it to cut that access.

Try it in your own workspace

7-day free trial · unlimited mailboxes · cancel anytime.