Creating and revoking API keys

Create a scoped key, store it safely, rotate it and revoke it when it leaks.

Updated Sep 10, 2026 1 min read

Create a key

  1. Go to Settings → API Keys.
  2. Click Create key.
  3. Name it after the system that will use it, so you know what breaks if you revoke it.
  4. Pick scopes. The dialog groups them as Blanket, Campaigns, Contacts, Sequences, Mailboxes, Analytics, Replies and Webhooks.
  5. Save, then copy the key.

The full key value is shown once, at creation. After that only a prefix is stored for identification, so MunchReach cannot show it to you again.

Revoke a key

In Settings → API Keys, revoke the key. Revocation takes effect on the next request, which then fails with api_key_revoked.

Rotation

Rotate by creating the replacement first, deploying it, confirming traffic on the new key, then revoking the old one. That avoids downtime.

Important notes

  • Give each integration its own key with the narrowest scopes it needs.
  • If a key ever appears in a log, a screenshot or a repository, revoke it immediately — there is no way to un-leak it.

Was this article helpful?

Related articles