Create and manage your API keys

API keys let you securely connect your website, application, or other tool to your Brevo account, so you can automate tasks like adding contacts, sending campaigns, or exporting data.

Good to know

  • Only the account owner or users with the API keys permission can access the API Keys & MCP page, create a new API key, or delete an existing API key. To learn more about user permissions and permission levels, check our dedicated article Add users and assign permissions in Brevo.
  • Whenever an API key is created or deleted from the account, the account owner will receive an email notification, including details such as the IP address and location.

What is an API key?

An API key is a code used to identify and authenticate an application or user. It acts as a unique identifier and provides a secret token for authentication purposes. For example, you can use an API key to connect your website or information system to Brevo. This will enable you to automatically and manually trigger certain actions between the two.

With an API key, you can also connect to our API to automatically add new contacts, as well as do more complex tasks, such as:

  • Creating and scheduling campaigns from the API.
  • Exporting users that belong to particular lists.
  • Exporting campaign statistics, etc.

To access the full list of commands that you can use with our API, check our API documentation.

Where can I find my API keys?

To protect your API keys and make them more secure, your existing API keys are not visible from your Brevo account. Only the last digits of the keys are displayed on the API Keys & MCP page so that you can distinguish between several keys if necessary:

API_keys.jpg

That's why we strongly suggest you store your API key in a safe environment when you create your API key. If you've lost your API key, we recommend you create a new one, store it in a safe environment, and replace the previous one.

❗️ Important
If the blocking of unknown IP addresses is activated on your account and Brevo detects an API call from an IP address you haven't used before, you'll receive a security email asking you to confirm or deny the activity. To learn more, check our dedicated article Authorize and block IP addresses for API and SMTP security.

Create an API key

When configuring an integration with your Brevo account, you may need to create a new API key:

  1. Click your account dropdown and select Settings > SMTP & API > API Keys & MCP.
  2. Click Generate a new API key.
    create_new_key.jpg
  3. Enter the verification code sent to your device and click Verify. To learn more, check our dedicated article Verify your identity for sensitive actions in Brevo.
  4. Name your API key. Make sure it specifies with which integration the API key will be used so that you can easily recognize it.
  5. Set an expiry date from 7 days to 1 year or choose no expiration for the API key.
    ❗️ Important

    Choosing No expiration only means the key has no fixed expiry date. It doesn't exempt it from Brevo's separate inactivity policy:

    • Expiration date reached: you'll receive an email reminder 3 days before and on the day the key expires.
    • 90 days of inactivity: even with no expiration date set, the key is deactivated if it hasn't made a successful API call in 90 days. You'll receive an email reminder 7 days before and on the day this happens.
  6. Click Generate.
    name_key.jpg
  7. Copy your API key and store it in a safe environment.
    ❗️ Important
    Your API key is only visible during this step. Once your API key is created, you won't be able to copy it anymore and you'll need to create a new one if you lose it.
    plugins_copy-api-key_en-us.png
  8. (Optional) Activate the Create MCP server API key option to generate a version of the API key allowing you to connect an AI system to Brevo via the MCP protocol. To learn more, check our dedicated article What is Model Context Protocol (MCP)?.
    💡 Good to know
    If you activate the Create MCP server API key, the API key created in step 4 is deactivated and a MCP version of the API key is generated instead.
  9. Click OK.

You have now successfully created a new API key.

Deactivate an API key

If you want to temporarily pause the usage of an API key instead of deleting it completely, you can deactivate it:

  1. Click your account dropdown and select Settings > SMTP & API > API Keys & MCP.
  2. Select the API key you want to deactivate.
  3. Click Deactivate API key.
    API_deactivate-key_en-us.png

You have now successfully deactivated your API key.

To reactivate a key, select it again and click Activate API key.

Delete an API key

❗️ Important
Deleting an API key is irreversible. Before deleting an API key, make sure you no longer use the integration that requires it or that you've replaced it with a new API key. If you delete an API key that is still being used, you'll experience integration failures.

If your account has been compromised or if you no longer use an integration that requires a particular API key, you can delete that API key:

  1. Click your account dropdown and select Settings > SMTP & API > API Keys & MCP.
  2. Select the API key you want to delete.
  3. Click Delete API key.delete_key.jpg

You have now successfully deleted your API key.

Best practices with API keys

API keys give full access to your Brevo account and should be protected in the same way as a password. Here are a few best practices to keep in mind when working with API keys:

  • Use a different API key for each integration and specify the name of the integration in the name of the API key so that you know exactly which key corresponds to each integration. That way, if an API key is compromised, you can delete it without impacting your other integrations.
  • Store your API keys in a safe environment, not in a Word document or post-it note.
  • Don't expose your API key to the public. Make sure you hide your API key, or even better, cut it completely in screenshots or videos.
  • Never send an API key via email, as this will give access to your Brevo account if someone hacks your email account.
  • Always delete API keys that are no longer used to limit the risks of leaks.
  • Keep your active keys used by making at least one successful API call every 90 days, even with no expiration date set, to avoid an unexpected deactivation. 
  • Activate IP address blocking so API calls from unrecognized IP addresses are blocked until you authorize them. To learn more, check our dedicated article Authorize and block IP addresses for API and SMTP security.

Troubleshoot issues with your API keys

If you're experiencing issues with your API keys, review the following troubleshooting tips before contacting our support team.

My API key shows "Expires: never" but I received an inactivity warning

You selected no expiration date when creating your API key, but you still received an email warning that the key will be deactivated for inactivity.

Common causes and solutions

The expiration date and the inactivity rule are two separate settings

Choosing No expiration only means the key has no fixed expiry date. It doesn't exempt the key from Brevo's inactivity policy: any API key that hasn't made a successful API call in 90 days can still be deactivated, regardless of its expiration setting.

Solution: Confirm that your integration is actually using this specific key (it may be using a different key from your account) and that it makes at least one successful API call before the 90-day window closes. If the key has already been deactivated, you can reactivate it.

Verify the fix

Make a test API call using the key, then check on the API Keys & MCP page that its status shows as active.

If the issue persists, contact our support team and include the last digits of the key and the exact warning message you received.

I received a "Verify a new IP" security email

You received an email from Brevo asking you to confirm or deny an API call made from an unrecognized IP address, and you're not sure whether it's legitimate or what to do next.

Common causes and solutions

An API call was made from an IP address not previously used on your account

If the blocking of unknown IP addresses is activated on your account, this email is sent whenever an API call is detected from an IP address that hasn't been used before. It doesn't necessarily mean something is wrong: it can be triggered by a legitimate integration (for example, a new server or third-party tool) connecting for the first time.

Solution: If you recognize the activity, authorize the new IP address from the email or from the Authorized IPs page. If you don't recognize it, deny it and change the affected API key immediately. To learn more, check our dedicated article Authorize and block IP addresses for API and SMTP security.

Verify the fix

Go to the Authorized IPs page and confirm the IP address shows the status you expect (authorized or removed).

If you keep receiving alerts for IP addresses you don't recognize after changing your API key, contact our support team.

⏭️ What's next?

🤔 Have a question?

If you have a question, feel free to contact our support team by creating a ticket from your account. If you don't have an account yet, you can contact us here.

If you’re looking for help with a project using Brevo, we can match you with the right certified Brevo Agency partner.

💬 Was this article helpful?

153 out of 239 found this helpful