AllyOneMail / Authentication

Authentication

Integrations authenticate with one API key per customer, with scopes. The dashboard uses a user session (JWT), which the API also accepts.

API key

X-API-Key: zm_live_...

Create the key in the AllyOneMail dashboard (or with POST /api/v1/auth/api-keys, using an admin key). The full value only appears at creation; AllyOneMail stores only its hash (SHA-256). If you lose it, generate another and revoke the old one. The zm_live_ prefix is inherited from the platform's former name.

Scopes

ScopeGrants
sendSending through /api/v1/send.
readReads: domains, events, suppressions, webhooks, billing, warm-up.
domainsRegister and change domains.
suppressOnly add suppressions (POST /api/v1/suppressions) — used to sync unsubscribes.
privacyData subject rights: /api/v1/privacy/export and /erasure.
adminEverything, including webhooks, users and keys. Use only where needed.

A call outside the key's scope responds 403 insufficient_scope.

Test the key

GET/api/v1/auth/me
curl https://smtp.allyone.com.br/api/v1/auth/me \
  -H "X-API-Key: zm_live_..."
{ "authType": "api_key", "clientId": "c1f0...", "agencyId": "a7d2...", "role": "api_key", "scopes": ["send", "read"] }

To check whether the API is up without authenticating: GET /api/status.

Rate limit

  • Per key: the per-minute limit configured on the key (default: 1,000). When exceeded, 429 api_rate_limit_exceeded; the counter resets the next minute.
  • Per IP: 500,000 requests per hour, with X-RateLimit-Limit, X-RateLimit-Remaining and X-RateLimit-Reset headers.

Details and error format in Errors and limits.

Full reference

The OpenAPI spec for every integration route is published at smtp.allyone.com.br/docs (JSON at /docs/json) — import it into Postman or Insomnia, or generate a client.

Authentication — AllyOneMail