Skip to content
Esc
  • OverviewGuidesWhat exists today, and where to start.
  • QuickstartGuidesKey, domain, first send — in that order.
  • AuthenticationGuidesBearer keys, the mandatory User-Agent, and what each refusal means.
  • ErrorsGuidesThe whole vocabulary, with the status each name carries.
  • IdempotencyGuidesRetry a send without sending it twice.
  • PaginationGuidesCursors are item IDs, not page numbers.
  • Rate limitsGuidesTen a second per team, and the headers that tell you where you are.
  • EventsGuidesEvery event a webhook can carry, with one real payload each.
  • DomainsGuidesThe records, where they go at each registrar, and what the page does while you wait.
  • TrackingGuidesOpens and clicks: one record, two toggles, and what an open really means.
  • ReceivingGuidesInbound mail, and the Inbox: a webhook fires, you read it, you answer it.
  • InboxGuidesChannels, personal mailboxes and seats: who sees what, and where a reply goes.
  • Node SDKGuidesThe rasket package: typed from the API's own document, retries only what is safe.
  • Python SDKGuidesThe rasket package on PyPI: the Node client's methods, in snake_case, over httpx.
  • MCP serverGuidesConnect Claude, ChatGPT or any MCP client: your scopes, no key.
  • AI assistGuidesSubject lines, drafts and diagnosis — in the dashboard and over the API, off until you allow it.
  • AgentsGuidesLet an AI agent set Rasket up: the skill, the rules file, MCP, and the recipe they share.
  • OAuthGuidesLet another app act for a team: register, authorize with PKCE, exchange, refresh.
  • Single sign-onGuidesOIDC login for your team, a domain proved by DNS, enforcement and break-glass.
  • IntegrationsGuidesVercel, Netlify and Cloudflare, plus Zapier and n8n for workflows without code.
  • SMTPGuidesSend from anything that speaks SMTP: settings, setup guides, limits and replies.
  • ZapierGuidesSend email, add contacts and react to email events from a Zap, with no code.
  • n8nGuidesThe Rasket node and trigger for n8n workflows: install, connect, every operation.
  • VercelGuidesAdd Rasket on Vercel: a Sending key in each project as RASKET_API_KEY, no copying.
  • EmailsAPI referenceSend, batch, retrieve, list, reschedule, cancel, attachments.
  • DomainsAPI referenceAdd a domain, publish its records, verify it.
  • API keysAPI referenceCreate, list, rename and revoke credentials.
  • WebhooksAPI referencePayloads, signature verification, retries and replay.
  • SuppressionsAPI referenceAddresses we will not send to, and why.
  • LogsAPI referenceEvery request made with this team's credentials.
  • MetricsAPI referenceDelivery, bounce, complaint and engagement counts.
  • TemplatesAPI referenceVersioned email content with typed variables, addressed by ID or alias.
  • ContactsAPI referenceYour audience: contacts, their typed properties, segments and topic choices.
  • SegmentsAPI referenceAudiences defined by a filter, by hand, or both.
  • TopicsAPI referenceWhat contacts subscribe to, and the preference page's list.
  • CampaignsAPI referenceCampaigns, at /broadcasts: one message to a segment, from draft to results.
  • ImportsAPI referenceCSV uploads: column mapping, conflicts and counts.
  • AutomationsAPI referenceWorkflows that run per contact: the graph, its versions, and every run.
  • Custom eventsAPI referenceThe names your product fires, and what starts a workflow.
  • ReceivingAPI referenceMail sent to you: the message, its attachments, its raw source.
  • OAuthAPI referenceClient registration, the token endpoint, and the grants a team has given.
  • TeamAPI referenceThe team a credential belongs to: its plan, sender identity, AI flag and members.
  • BillingAPI referencePlan, usage, invoices and add-ons, and the hosted pages where a customer pays.
  • AI helpersAPI referenceSubject lines, a first draft, and why an email did what it did.

API referenceAPI keys

API keys

A key is a bearer credential scoped to one team. It is shown once, stored as a hash, and can be narrowed to a single domain.

Permissions

The two key permissions
PermissionReachesUse it for
full_accessEvery endpoint, including creating and revoking other keys.Your server, when it genuinely needs to manage domains and keys.
sending_accessSending only. Any other endpoint answers 401 restricted_api_key.Anything whose job is to send mail — which is most things.

A sending_access key may also carry domain_id, which pins it to one verified domain: a request whose from is on any other domain is refused. A full_access key carrying domain_id is rejected at creation rather than silently ignored.

Handling the token

  • The token starts with rk_ and is returned by the create response and nowhere else. We store only its hash, so a lost token cannot be recovered — mint a new key and revoke the old one.
  • Keep it in an environment variable or a secret manager. Every example on this site reads it from the environment for that reason.
  • last_used_at on the list endpoint tells you whether a key is still in use before you revoke it.

If a key is exposed, revoke it first and investigate second. Revocation takes effect on the next request, and the row is kept so your audit history still reads correctly.

Endpoints

Create an API key

POST /api-keys

Mint a key and read its token — once.

Body

  • namestringRequired

    What the key is for, up to 255 characters. It appears in the dashboard and in audit records.

  • permissionstring

    full_access (the default) reaches every endpoint. sending_access may only send.

  • domain_idstring

    Restrict the key to one verified domain. Allowed only with sending_access; a full_access key carrying it is refused.

Request

curl -X POST "https://api.rasket.com/api-keys" \
  -H "Authorization: Bearer $RASKET_API_KEY" \
  -H "User-Agent: acme-billing/1.0" \
  -H "Content-Type: application/json" \
  -d '{
  "name": "billing worker",
  "permission": "sending_access",
  "domain_id": "d91a7b60-1a5f-4a2e-9d1b-0d9f2c7a1e34"
}'

Response 201

{
  "id": "a4d2f0c8-5b31-4e7a-9c62-8f0b1d4e6a75",
  "token": "rk_7Hq2Lm9Pu8jzPde0IgxLd6GncfBAepfJBd0Kh8oOOL8dKLzdocJ"
}
  • token is returned by this response and never again. Store it before you close the connection; we keep only its hash.
  • A key inherits the team it was created in. It cannot reach another team's data.

List API keys

GET /api-keys

Every key on the team, without its token.

Query parameters

  • limitinteger

    How many items to return, 1–100. Defaults to 20.

  • afterstring

    Return the page that follows this item ID. Mutually exclusive with before.

  • beforestring

    Return the page that precedes this item ID. Mutually exclusive with after.

  • statusstring

    active (the default: every key that is not revoked, suspended ones included), revoked or all.

  • searchstring

    Keep keys whose name contains this text, ignoring case. % and _ are ordinary characters here. A blank value is refused.

  • permissionstring

    Keep only full_access or only sending_access keys.

Request

curl -X GET "https://api.rasket.com/api-keys" \
  -H "Authorization: Bearer $RASKET_API_KEY" \
  -H "User-Agent: acme-billing/1.0"

Response 200

{
  "object": "list",
  "has_more": false,
  "data": [
    {
      "id": "a4d2f0c8-5b31-4e7a-9c62-8f0b1d4e6a75",
      "name": "billing worker",
      "created_at": "2026-09-09T09:11:07.552Z",
      "last_used_at": "2026-09-09T10:14:02.118Z",
      "permission": "sending_access",
      "domain_id": "d91a7b60-1a5f-4a2e-9d1b-0d9f2c7a1e34",
      "key_prefix": "rk_7Hq2Lm9P",
      "status": "active",
      "last_used_request_log_id": "0198f4c1-0000-7000-8000-000000000000"
    }
  ]
}
  • last_used_at is refreshed at most once a minute while a key is in use, so it tells you whether a key is still in use before you revoke it.

Rename an API key

PATCH /api-keys/{api_key_id}

Change the name. Nothing else about a key is editable.

Path parameters

  • api_key_idstringRequired

    The key's ID.

Body

  • namestringRequired

    The new name.

Request

curl -X PATCH "https://api.rasket.com/api-keys/a4d2f0c8-5b31-4e7a-9c62-8f0b1d4e6a75" \
  -H "Authorization: Bearer $RASKET_API_KEY" \
  -H "User-Agent: acme-billing/1.0" \
  -H "Content-Type: application/json" \
  -d '{
  "name": "billing worker (eu)"
}'

Response 200

{
  "object": "api_key",
  "id": "a4d2f0c8-5b31-4e7a-9c62-8f0b1d4e6a75"
}
  • Permission and domain restriction are fixed at creation. To change either, create a new key and revoke this one.

Revoke an API key

DELETE /api-keys/{api_key_id}

Stop the key working, immediately and permanently.

Path parameters

  • api_key_idstringRequired

    The key's ID.

Request

curl -X DELETE "https://api.rasket.com/api-keys/a4d2f0c8-5b31-4e7a-9c62-8f0b1d4e6a75" \
  -H "Authorization: Bearer $RASKET_API_KEY" \
  -H "User-Agent: acme-billing/1.0"

Response 200

{
  "object": "api_key",
  "id": "a4d2f0c8-5b31-4e7a-9c62-8f0b1d4e6a75",
  "deleted": true
}
  • The row is kept so your audit history stays readable; only the credential stops working.
  • A revoked key answers 403 restricted_api_key, which is a different answer from an unknown key's 401 invalid_api_key.