API

Manage your organization's API keys for programmatic access to Yaplet and integration with external services.

What is an API Key?

An API key is a secure token that provides full access to your Yaplet organization's data and features. It's required for all API calls and should be kept secure.

Key Points

  • Organization-level: Your organization can have up to 10 named keys, shared across your team — all of them work at the same time
  • One-time display: A key's secret is shown only once, when it is created - save it immediately
  • Full access: Every key provides complete access to your account data through Yaplet's APIs. Whether an AI app may use the key is a separate setting, AI access (MCP), which starts off
  • On every plan: API keys are part of the free base — you do not need a paid plan to create one
API access is now included on every plan, the free one included. It used to be part of the Growth bundle only, which meant a Starter customer who had bought a module that needs a key — affiliate tracking, AI social posting, newsletter workflows — could not create one. Existing organisations were given the permission automatically; there is nothing to buy and nothing to switch on.
Being able to create a key does not grant you features. Every endpoint a key can reach still checks its own permission, so a key on a free organisation opens exactly what that organisation already has.

Managing Your API Keys

Go to Settings → Organization settings → API (the screen itself is headed API Keys). Your keys are listed in a table showing each key's name, its ending (yAPI_… plus the last 6 characters of the secret, so you can match a key against the one in your config), its creation date, when it was last used, and its AI access (MCP) setting.

Last used shows when a request last arrived with the key. Every request carrying it counts, even one Yaplet then refused. It updates at most every 15 minutes, so for a busy key the time can be up to 15 minutes old. A key that hasn't been used since this column was added shows Not recorded yet.

Creating a Key

  1. Click "New API Key"
  2. Give the key a name describing what it will be used for — e.g. Production server (required)
  3. Copy and save the secret immediately - it cannot be retrieved again; Yaplet only stores a hash of it
  4. Keys are prefixed with yAPI_ for easy identification
Create one dedicated key per integration. That way you can later delete any key without breaking the others.

Deleting a Key

Deleting asks you to type the key's name to confirm. The key stops working immediately and cannot be restored — anything still using it will fail.

To swap a key without downtime: create a new key, switch your integration over to it, then delete the old one.

Keys created before named keys existed are called Default API key, and their row shows a bare yAPI_… — their ending was never stored.

Using Your API Key

Include any of your API keys in the Y-API-Key header for all API requests:

Y-API-Key: yAPI_your_generated_key_here

API Use Cases

Your API keys enable various integrations such as:

  • Affiliate tracking - Record referrals and commissions
  • Newsletter subscriber management - Bulk import and update contacts
  • Email automation triggers - Start an email automation for a contact programmatically
  • Custom integrations - Connect Yaplet with your existing systems
Detailed API documentation for each endpoint is available on their respective documentation pages:

AI access (MCP)

An API key is also one of the ways an AI app connects to your account through the MCP server. The AI access (MCP) column decides, key by key, whether that is allowed and how much the AI may do:

SettingWhat an AI app using this key may do
OffNothing — the AI app is refused. The key keeps working for Yaplet's other APIs.
Read onlyLook things up. It changes nothing.
Read and changeAlso create and update things that can be changed back.
Read, change, delete and sendAlso delete a record for good, or send a message to someone outside your team.
  • New keys start Off. Switch AI access on only for a key you actually use with an AI app.
  • A key runs as the person who switched it on. The AI can then do only what that person may do in the dashboard right now. The row shows who it runs as — Runs as …. If that person is disabled, the key's AI access stops until they are re-enabled; if they are removed from the organization, it stops for good — the row then says Runs as a removed member, and since only a key's creator can switch it on, create a new key instead.
  • Only the key's creator can switch its AI access on or change its level, so nobody can turn a colleague's key into an AI key that runs as them. Anyone who can open this page can switch it Off. For keys created before creators were recorded, only the organization owner can switch it on.
  • Older keys: keys that existed before this setting kept full AI access and run as the organization owner (Runs as the organization owner). If you don't use such a key with an AI app, switch its AI access off.
  • Every change of this setting is written to the Audit Log as API key AI access changed, and every change an AI makes through the key is logged there with the key's name.
Whatever its AI access, the key itself is still a full-access secret for Yaplet's APIs. Treat it like a password.

Security

Security best practices:
  • Store keys securely (environment variables, secret managers)
  • Never commit keys to version control
  • To replace a key, create a new one, switch your integration over, then delete the old key
  • Limit access to necessary team members