sevk uses bearer API keys scoped to a single project. Each key carries a fixed set of capability scopes and can optionally be pinned to one verified domain.
API keys
An API key belongs to exactly one project. Every resource read or written through the API (emails, contacts, audiences, broadcasts, domains) is implicitly filtered by that project id. There is no way to reach another project's data with a given key, even at the 404 level.
Create and revoke keys from the sevk dashboard under Settings → API Keys. Revocation takes effect on the next request.
Sending the key
Pass the key as a bearer token on every request:
Authorization: Bearer sevk_xxxxxxxxx
curl https://api.sevk.io/emails \
-H "Authorization: Bearer sevk_xxxxxxxxx" \
-H "Content-Type: application/json"
Through the SDK
The clients take the key in their constructor and attach the header themselves:
Node.js
import{ Sevk }from'sevk'
const sevk =newSevk(process.env.SEVK_API_KEY!)
Python
import os
from sevk import Sevk
sevk = Sevk(os.environ['SEVK_API_KEY'])
Domain-pinned keys
An API key can optionally be bound to a single verified domain. When a key has a domainId, every POST /emails, POST /emails/bulk, and POST /broadcasts/:id/send request is inspected: if the from address (or the broadcast's domainId) is not on that domain, the request is rejected with 403 before any queue work happens. Pinning is the right choice for per-tenant sending where one key must never send as another tenant.
Sending from multiple regions
When the same hostname is registered in several regions, bind each sending key to the domain record for the region you want to use. A key bound to example.com in eu-central-1 sends from that region; a key bound to its eu-west-1 record sends from Ireland. Both can use [email protected] as the sender. This applies to single sends, bulk sends, and SMTP authentication. Broadcasts use the region of their selected domain record.
Keys scoped to all domains do not select a specific region when several verified records match the sender. Use a domain-pinned key when region selection matters. sevk does not automatically switch regions when a send fails.
Capability scopes
Every endpoint checks one or more capabilities on the presenting key. A key can be issued with full access, or with an arbitrary subset of scopes. Revoking a scope takes effect on the next request. No token re-issue required.
Emails
Name
Type
Description
email:send
capability
POST /emails and POST /emails/bulk.
email:read
capability
GET /emails/:id: read a specific email record.
Contacts
Name
Type
Description
contact:read
capability
List and read contacts within an audience.
contact:write
capability
Create and update contacts; updates resubscriptionLocked state when contacts resubscribe.
contact:delete
capability
Delete contacts. Removes the contact from every audience and topic it belonged to.
Audiences
Name
Type
Description
audience:read
capability
List and read audiences (includes contactCount).
audience:write
capability
Create and update audiences.
audience:delete
capability
Delete audiences and their contacts.
Templates
Name
Type
Description
template:read
capability
List and read templates.
template:write
capability
Create and update templates.
template:delete
capability
Delete templates.
Broadcasts
Name
Type
Description
broadcast:read
capability
List and read broadcasts, analytics, and broadcast-specific cost/delivery detail.
broadcast:write
capability
Create and update broadcasts (draft state).
broadcast:delete
capability
Delete broadcasts.
broadcast:send
capability
Trigger a send. Deducts per-recipient cost from the project balance.
Domains
Name
Type
Description
domain:read
capability
List and read domain records and verification status.
domain:write
capability
Add, update, and trigger verification on domains.
domain:delete
capability
Delete domains. Keys pinned to the domain are orphaned.
domain:dns-read
capability
Read the DKIM/SPF/return-path records sevk expects.
Topics
Name
Type
Description
topic:read
capability
List and read topics (includes contactCount).
topic:write
capability
Create and update topics.
topic:delete
capability
Delete topics.
Segments
Name
Type
Description
segment:read
capability
List and read segments and their resolved contacts.
segment:write
capability
Create and update segment filter rules.
segment:delete
capability
Delete segments.
Subscriptions
Name
Type
Description
subscription:subscribe
capability
Subscribe a contact to a topic. Returns 403 if resubscriptionLocked is true on an unsubscribed contact.
subscription:unsubscribe
capability
Unsubscribe a contact globally. Marks the contact unsubscribed; it does not set resubscriptionLocked.
Webhooks
Name
Type
Description
webhook:read
capability
List and read webhook endpoints.
webhook:write
capability
Create and update webhook endpoints and event filters.
webhook:delete
capability
Delete webhook endpoints.
Activity
Name
Type
Description
activity:read
capability
Read the activity log (opens, clicks, bounces, complaints, deliveries, and other email events).
Usage
Name
Type
Description
limits:read
capability
Read GET /limits: project balance, plan limits, and current resource counts.
Outbound
Name
Type
Description
outbound:read
capability
Read the outbound monthly quota, usage, reset time, and pause state.
outbound:write
capability
Update the outbound quota limit and pause or resume outbound sending.
Inbound
Name
Type
Description
inbound:read
capability
List and read inbound emails, routes, and blocklist entries.
inbound:write
capability
Create and update inbound routing and settings.
inbound:delete
capability
Delete inbound emails, routes, and blocklist entries.
AI
Name
Type
Description
ai:generate
capability
Generate email markup with AI.
Key hygiene
Server-side only. Keys carry full send authority for the project. Never embed one in a mobile app, desktop app, or browser bundle.
One key per integration. If a key leaks, you want to revoke it without taking down the rest of your stack.
Scope minimally. A webhook worker that only looks up emails should have email:read, not email:send.
Pin to a domain when you can. A pinned key can only send as that domain even if it is exfiltrated.
Rotate on suspicion. Keys are cheap to issue. Rotate before you investigate, not after.