Skip to documentation

Get started

Create an API key

Authenticate server requests with a team-scoped key.

Create your key

Open API keys in your dashboard and choose Create API key. Any team member can create, edit, and remove keys. Fill in three fields:

  • Name: up to 50 characters.
  • Permission: Full access can create, delete, get, and update any resource. Sending access can only send emails. Full access is selected by default.
  • Domain: only a sending-access key can be restricted to a single domain. It is All domains otherwise.

The domain selector searches your team’s domains on the server. Type a domain name to find entries beyond the initial options; the current selection stays visible while you search.

You can also create keys with POST /api-keys using a full-access key.

Store the token

The token starts with os_ and is shown once, in the View API Key dialog. Opensend stores only its hash and cannot show the token again; afterwards the list shows its first characters and last four. Keep it on your server, outside client bundles and source control.

dotenv
OPENSEND_API_KEY=os_replace_me
OPENSEND_BASE_URL=https://api.example.com

The same token is the password for SMTP.

Try it

bash
curl "$OPENSEND_BASE_URL/emails" \
  -H "Authorization: Bearer $OPENSEND_API_KEY" \
  -H "Content-Type: application/json" \
  -d '{"from":"Acme <hello@example.com>","to":["you@example.net"],"subject":"Hello from Opensend","html":"<p>Your first email is on its way.</p>"}'

What each permission can do

A sending key reaches POST /emails, POST /emails/batch, and SMTP. On any other endpoint it receives 401 restricted_api_key. A key restricted to a domain can only send from that domain. If that domain is removed, the key does not become unrestricted: it can no longer send and receives 403 restricted_api_key.

All of a team’s keys share one limit of 10 requests per second.

Edit or remove a key

Editing a key changes its name, permission, or domain without changing the token. Removing a key takes effect immediately: later requests signed with it fail, including messages on an SMTP connection that is already authenticated. Create a replacement before you remove a key that is in use.