Authentication
Integrations authenticate with one API key per customer, with scopes. The dashboard uses a user session (JWT), which the API also accepts.
API key
X-API-Key: zm_live_...
Create the key in the AllyOneMail dashboard (or with POST /api/v1/auth/api-keys, using an admin key). The full value only appears at creation; AllyOneMail stores only its hash (SHA-256). If you lose it, generate another and revoke the old one. The zm_live_ prefix is inherited from the platform's former name.
Scopes
| Scope | Grants |
|---|---|
send | Sending through /api/v1/send. |
read | Reads: domains, events, suppressions, webhooks, billing, warm-up. |
domains | Register and change domains. |
suppress | Only add suppressions (POST /api/v1/suppressions) — used to sync unsubscribes. |
privacy | Data subject rights: /api/v1/privacy/export and /erasure. |
admin | Everything, including webhooks, users and keys. Use only where needed. |
A call outside the key's scope responds 403 insufficient_scope.
Test the key
curl https://smtp.allyone.com.br/api/v1/auth/me \
-H "X-API-Key: zm_live_..."
{ "authType": "api_key", "clientId": "c1f0...", "agencyId": "a7d2...", "role": "api_key", "scopes": ["send", "read"] }
To check whether the API is up without authenticating: GET /api/status.
Rate limit
- Per key: the per-minute limit configured on the key (default: 1,000). When exceeded,
429api_rate_limit_exceeded; the counter resets the next minute. - Per IP: 500,000 requests per hour, with
X-RateLimit-Limit,X-RateLimit-RemainingandX-RateLimit-Resetheaders.
Details and error format in Errors and limits.
Full reference
The OpenAPI spec for every integration route is published at smtp.allyone.com.br/docs (JSON at /docs/json) — import it into Postman or Insomnia, or generate a client.
