API
Manage your organization's API keys for programmatic access to Yaplet and integration with external services.
What is an API Key?
An API key is a secure token that provides full access to your Yaplet organization's data and features. It's required for all API calls and should be kept secure.
Key Points
- Organization-level: Your organization can have up to 10 named keys, shared across your team — all of them work at the same time
- One-time display: A key's secret is shown only once, when it is created - save it immediately
- Full access: Every key provides complete access to your account data through Yaplet's APIs. Whether an AI app may use the key is a separate setting, AI access (MCP), which starts off
- On every plan: API keys are part of the free base — you do not need a paid plan to create one
Managing Your API Keys
Go to Settings → Organization settings → API (the screen itself is headed API Keys). Your keys are listed in a table showing each key's name, its ending (yAPI_… plus the last 6 characters of the secret, so you can match a key against the one in your config), its creation date, when it was last used, and its AI access (MCP) setting.
Last used shows when a request last arrived with the key. Every request carrying it counts, even one Yaplet then refused. It updates at most every 15 minutes, so for a busy key the time can be up to 15 minutes old. A key that hasn't been used since this column was added shows Not recorded yet.
Creating a Key
- Click "New API Key"
- Give the key a name describing what it will be used for — e.g. Production server (required)
- Copy and save the secret immediately - it cannot be retrieved again; Yaplet only stores a hash of it
- Keys are prefixed with
yAPI_for easy identification
Deleting a Key
Deleting asks you to type the key's name to confirm. The key stops working immediately and cannot be restored — anything still using it will fail.
To swap a key without downtime: create a new key, switch your integration over to it, then delete the old one.
yAPI_… — their ending was never stored.Using Your API Key
Include any of your API keys in the Y-API-Key header for all API requests:
Y-API-Key: yAPI_your_generated_key_here
API Use Cases
Your API keys enable various integrations such as:
- Affiliate tracking - Record referrals and commissions
- Newsletter subscriber management - Bulk import and update contacts
- Email automation triggers - Start an email automation for a contact programmatically
- Custom integrations - Connect Yaplet with your existing systems
AI access (MCP)
An API key is also one of the ways an AI app connects to your account through the MCP server. The AI access (MCP) column decides, key by key, whether that is allowed and how much the AI may do:
| Setting | What an AI app using this key may do |
|---|---|
| Off | Nothing — the AI app is refused. The key keeps working for Yaplet's other APIs. |
| Read only | Look things up. It changes nothing. |
| Read and change | Also create and update things that can be changed back. |
| Read, change, delete and send | Also delete a record for good, or send a message to someone outside your team. |
- New keys start Off. Switch AI access on only for a key you actually use with an AI app.
- A key runs as the person who switched it on. The AI can then do only what that person may do in the dashboard right now. The row shows who it runs as — Runs as …. If that person is disabled, the key's AI access stops until they are re-enabled; if they are removed from the organization, it stops for good — the row then says Runs as a removed member, and since only a key's creator can switch it on, create a new key instead.
- Only the key's creator can switch its AI access on or change its level, so nobody can turn a colleague's key into an AI key that runs as them. Anyone who can open this page can switch it Off. For keys created before creators were recorded, only the organization owner can switch it on.
- Older keys: keys that existed before this setting kept full AI access and run as the organization owner (Runs as the organization owner). If you don't use such a key with an AI app, switch its AI access off.
- Every change of this setting is written to the Audit Log as API key AI access changed, and every change an AI makes through the key is logged there with the key's name.
Security
- Store keys securely (environment variables, secret managers)
- Never commit keys to version control
- To replace a key, create a new one, switch your integration over, then delete the old key
- Limit access to necessary team members