Skip to content
Esc
  • OverviewGuidesWhat exists today, and where to start.
  • QuickstartGuidesKey, domain, first send — in that order.
  • AuthenticationGuidesBearer keys, the mandatory User-Agent, and what each refusal means.
  • ErrorsGuidesThe whole vocabulary, with the status each name carries.
  • IdempotencyGuidesRetry a send without sending it twice.
  • PaginationGuidesCursors are item IDs, not page numbers.
  • Rate limitsGuidesTen a second per team, and the headers that tell you where you are.
  • EventsGuidesEvery event a webhook can carry, with one real payload each.
  • DomainsGuidesThe records, where they go at each registrar, and what the page does while you wait.
  • TrackingGuidesOpens and clicks: one record, two toggles, and what an open really means.
  • TemplatesGuidesFifty-seven starters sorted by goal, and how to keep a campaign as a template.
  • ReceivingGuidesInbound mail, and the Inbox: a webhook fires, you read it, you answer it.
  • InboxGuidesChannels, personal mailboxes and seats: who sees what, and where a reply goes.
  • Mail appsGuidesComing soon: your Rasket address in Apple Mail, Outlook and the Gmail app.
  • Inbox APIGuidesOpen, read and answer support conversations from your app, with the same key.
  • Support inbox in your appGuidesA Contact us form that opens a conversation your team answers, in five minutes.
  • Replies to your emailsGuidesOne field on a send, and the customer's reply opens a conversation.
  • Let an agent triageGuidesAn AI agent reads, notes and drafts over MCP; a person sends.
  • Node SDKGuidesThe rasket package: typed from the API's own document, retries only what is safe.
  • Python SDKGuidesThe rasket package on PyPI: the Node client's methods, in snake_case, over httpx.
  • MCP serverGuidesConnect Claude, ChatGPT or any MCP client: your scopes, no key.
  • AI assistGuidesSubject lines, drafts and diagnosis — in the dashboard and over the API, off until you allow it.
  • AgentsGuidesLet an AI agent set Rasket up: the skill, the rules file, MCP, and the recipe they share.
  • OAuthGuidesLet another app act for a team: register, authorize with PKCE, exchange, refresh.
  • Single sign-onGuidesOIDC login for your team, a domain proved by DNS, enforcement and break-glass.
  • IntegrationsGuidesVercel, Netlify and Cloudflare, Zapier and n8n, a WordPress plugin, and Notion contacts.
  • SMTPGuidesSend from anything that speaks SMTP: settings, setup guides, limits and replies.
  • ZapierGuidesSend email, add contacts and react to email events from a Zap, with no code.
  • n8nGuidesThe Rasket node and trigger for n8n workflows: install, connect, every operation.
  • VercelGuidesAdd Rasket on Vercel: a Sending key in each project as RASKET_API_KEY, no copying.
  • WordPressGuidesThe Rasket plugin: every email your site sends, through Rasket, with a safe fallback.
  • NotionGuidesTurn a Notion database of people into contacts in a segment, once or every hour.
  • Migrating to RasketGuidesBring contacts, unsubscribes, lists and templates from Mailchimp, Klaviyo and more.
  • EmailsAPI referenceSend, batch, retrieve, list, reschedule, cancel, attachments.
  • DomainsAPI referenceAdd a domain, publish its records, verify it.
  • API keysAPI referenceCreate, list, rename and revoke credentials.
  • WebhooksAPI referencePayloads, signature verification, retries and replay.
  • SuppressionsAPI referenceAddresses we will not send to, and why.
  • LogsAPI referenceEvery request made with this team's credentials.
  • MetricsAPI referenceDelivery, bounce, complaint and engagement counts.
  • TemplatesAPI referenceVersioned email content with typed variables, addressed by ID or alias.
  • ContactsAPI referenceYour audience: contacts, their typed properties, segments and topic choices.
  • SegmentsAPI referenceAudiences defined by a filter, by hand, or both.
  • TopicsAPI referenceWhat contacts subscribe to, and the preference page's list.
  • CampaignsAPI referenceCampaigns, at /broadcasts: one message to a segment, from draft to results.
  • ImportsAPI referenceCSV uploads: column mapping, conflicts and counts.
  • AutomationsAPI referenceWorkflows that run per contact: the graph, its versions, and every run.
  • Custom eventsAPI referenceThe names your product fires, and what starts a workflow.
  • ReceivingAPI referenceMail sent to you: the message, its attachments, its raw source.
  • OAuthAPI referenceClient registration, the token endpoint, and the grants a team has given.
  • TeamAPI referenceThe team a credential belongs to: its plan, sender identity, AI flag and members.
  • BillingAPI referencePlan, usage, invoices and add-ons, and the hosted pages where a customer pays.
  • AI helpersAPI referenceSubject lines, a first draft, and why an email did what it did.
  • InboxAPI referenceChannels, conversations, messages, notes and search in your support inbox.

API referenceAPI keys

API keys

A key is a bearer credential scoped to one team. It is shown once, stored as a hash, and can be narrowed to a single domain.

Permissions

The two key permissions
PermissionReachesUse it for
full_accessEvery endpoint, including creating and revoking other keys.Your server, when it genuinely needs to manage domains and keys.
sending_accessSending only. Any other endpoint answers 401 restricted_api_key.Anything whose job is to send mail — which is most things.

A sending_access key may also carry domain_id, which pins it to one verified domain: a request whose from is on any other domain is refused. A full_access key carrying domain_id is rejected at creation rather than silently ignored.

Handling the token

  • The token starts with rk_ and is returned by the create response and nowhere else. We store only its hash, so a lost token cannot be recovered — mint a new key and revoke the old one.
  • Keep it in an environment variable or a secret manager. Every example on this site reads it from the environment for that reason.
  • last_used_at on the list endpoint tells you whether a key is still in use before you revoke it.

If a key is exposed, revoke it first and investigate second. Revocation takes effect on the next request, and the row is kept so your audit history still reads correctly.

Endpoints

Create an API key

POST /api-keys

Mint a key and read its token — once.

Body

  • namestringRequired

    What the key is for, up to 255 characters. It appears in the dashboard and in audit records.

  • permissionstring

    full_access (the default) reaches every endpoint. sending_access may only send.

  • domain_idstring

    Restrict the key to one verified domain. Allowed only with sending_access; a full_access key carrying it is refused.

2 more fields (inbox_access, inbox_channel_ids)
  • inbox_accessstring

    What the key may do in your support Inbox: none (the default), create (open conversations only), read, or write (read and reply). Separate from permission: a full_access key still has none until you raise it. Anything above none needs a team admin, signed in to the dashboard.

  • inbox_channel_idsstring[] | null

    Limit the key's Inbox access to these channels. Null or absent means every open channel that is not restricted; a restricted channel is reachable only by a key limited to it. Needs a team admin, signed in to the dashboard.

Request

curl -X POST "https://api.rasket.com/api-keys" \
  -H "Authorization: Bearer $RASKET_API_KEY" \
  -H "User-Agent: acme-billing/1.0" \
  -H "Content-Type: application/json" \
  -d '{
  "name": "billing worker",
  "permission": "sending_access",
  "domain_id": "d91a7b60-1a5f-4a2e-9d1b-0d9f2c7a1e34"
}'

Response 201

{
  "id": "a4d2f0c8-5b31-4e7a-9c62-8f0b1d4e6a75",
  "token": "rk_7Hq2Lm9Pu8jzPde0IgxLd6GncfBAepfJBd0Kh8oOOL8dKLzdocJ"
}
  • token is returned by this response and never again. Store it before you close the connection; we keep only its hash.
  • A key inherits the team it was created in. It cannot reach another team's data.

List API keys

GET /api-keys

Every key on the team, without its token.

Query parameters

  • limitinteger

    How many items to return, 1–100. Defaults to 20.

  • afterstring

    Return the page that follows this item ID. Mutually exclusive with before.

  • beforestring

    Return the page that precedes this item ID. Mutually exclusive with after.

  • statusstring

    active (the default: every key that is not revoked, suspended ones included), revoked or all.

  • searchstring

    Keep keys whose name contains this text, ignoring case. % and _ are ordinary characters here. A blank value is refused.

  • permissionstring

    Keep only full_access or only sending_access keys.

  • inbox_accessstring

    Keep only keys with this Inbox access: none, create, read or write.

Request

curl -X GET "https://api.rasket.com/api-keys" \
  -H "Authorization: Bearer $RASKET_API_KEY" \
  -H "User-Agent: acme-billing/1.0"

Response 200

{
  "object": "list",
  "has_more": false,
  "data": [
    {
      "id": "a4d2f0c8-5b31-4e7a-9c62-8f0b1d4e6a75",
      "name": "billing worker",
      "created_at": "2026-09-09T09:11:07.552Z",
      "last_used_at": "2026-09-09T10:14:02.118Z",
      "permission": "sending_access",
      "domain_id": "d91a7b60-1a5f-4a2e-9d1b-0d9f2c7a1e34",
      "key_prefix": "rk_7Hq2Lm9P",
      "status": "active",
      "last_used_request_log_id": "0198f4c1-0000-7000-8000-000000000000",
      "inbox_access": "none",
      "inbox_channel_ids": null
    }
  ]
}
  • last_used_at is refreshed at most once a minute while a key is in use, so it tells you whether a key is still in use before you revoke it.

Rename an API key or change its Inbox access

PATCH /api-keys/{api_key_id}

Change the name, the Inbox access, or the channels it is limited to.

Path parameters

  • api_key_idstringRequired

    The key's ID.

Body

  • namestring

    The new name.

2 more fields (inbox_access, inbox_channel_ids)
  • inbox_accessstring

    none, create, read or write. Raising it needs a team admin, signed in to the dashboard; lowering it to none does not, and clears the channels.

  • inbox_channel_idsstring[] | null

    The channels the key is limited to. null lifts the limit, which widens the key, so any change needs a team admin, signed in to the dashboard.

Request

curl -X PATCH "https://api.rasket.com/api-keys/a4d2f0c8-5b31-4e7a-9c62-8f0b1d4e6a75" \
  -H "Authorization: Bearer $RASKET_API_KEY" \
  -H "User-Agent: acme-billing/1.0" \
  -H "Content-Type: application/json" \
  -d '{
  "name": "billing worker (eu)"
}'

Response 200

{
  "object": "api_key",
  "id": "a4d2f0c8-5b31-4e7a-9c62-8f0b1d4e6a75"
}
  • Permission and domain restriction are fixed at creation. To change either, create a new key and revoke this one.
  • Send any of name, inbox_access and inbox_channel_ids. A revoked key is 404.

Revoke an API key

DELETE /api-keys/{api_key_id}

Stop the key working, immediately and permanently.

Path parameters

  • api_key_idstringRequired

    The key's ID.

Request

curl -X DELETE "https://api.rasket.com/api-keys/a4d2f0c8-5b31-4e7a-9c62-8f0b1d4e6a75" \
  -H "Authorization: Bearer $RASKET_API_KEY" \
  -H "User-Agent: acme-billing/1.0"

Response 200

{
  "object": "api_key",
  "id": "a4d2f0c8-5b31-4e7a-9c62-8f0b1d4e6a75",
  "deleted": true
}
  • The row is kept so your audit history stays readable; only the credential stops working.
  • A revoked key answers 403 restricted_api_key, which is a different answer from an unknown key's 401 invalid_api_key.