NOTICEAPI
Pricing
Sign inGet API key
Product
OverviewSend, receive, and operate emailTransactional emailReliable receipts, resets, and alertsMarketing emailCampaigns, audiences, and lifecycleAutomationsAudience-triggered sequencesTemplatesStore, render, and sendReceivingRoute replies into your applicationSMS — coming soonJoin the private-preview listMCP serverLet a coding agent operate email
Solutions
AgenciesKeep every client project organizedSaaS teamsLifecycle email without tool sprawlIndie buildersA production path that starts at $0AI-assisted developmentScoped access for coding agents
Developers
DocumentationBuild and operate your email pathQuickstartSend your first customer emailAPI referenceRequests, responses, and errorsSDKTyped Node.js integrationAgents and MCPBound every agent to its jobIntegrationsFramework and product guidesSimulatorTest outcomes without real delivery
Pricing
Sign inGet API key

Scoped API keys

Every key gets
one clear job.

Choose exactly which capabilities, projects, and sender domains a workflow can use. A key can create another grant only when it has api-keys:write — and never one broader than itself.

Create accountOpen API keys
  • Secret shown once
  • Immediate revocation
  • Server-side credentials
Access grantProduction senderScoped
API keyntc_xxxxxxxxxxxxxxxxxxxxShown once
Sending onlyCustomFull access
Capabilityemail:sendSelected
ProjectAcme AppSelected
Sender domainnotify.acme.comSelected
Ready for server useRevoke instantly
Starts with ntc_Scopes never widenProject boundedDomain bounded

Three boundaries

Define what it can do — and where.

Capabilities control the operation. Projects control the data boundary. Sender domains control which verified identities a sending workflow may use.

Capability groupScopes
MessagingSend and operate runtime channelsemail:send
WorkspaceProjects, credentials, and domainsprojects:readprojects:writeapi-keys:writedomains:readdomains:write
ContentTemplates and consent-based lifecycle mailtemplates:writeaudiences:writebroadcasts:writeautomations:write
OperationsEvents, recipient policy, and inbound emailwebhooks:writesuppressions:writereceiving:readreceiving:write

Canonical capability list

The public scope list comes from the product.

This page renders the same canonical capability array used by the API. Choose a full, sending-only, or custom preset; custom grants can combine any current scopes below with selected projects and domains.

Read the agent access guide
Scopes a key can carry
[
  "email:send",
  "sms:send",
  "sms:read",
  "sms:manage",
  "sms:billing:read",
  "projects:read",
  "projects:write",
  "api-keys:write",
  "domains:read",
  "domains:write",
  "templates:write",
  "audiences:write",
  "broadcasts:write",
  "automations:write",
  "webhooks:write",
  "suppressions:write",
  "receiving:read",
  "receiving:write"
]

Credential lifecycle

Create narrowly. Rotate cleanly.

Separate credentials keep routine rotation or one revoked workflow from touching every integration in the workspace.

  1. 01GrantChoose the job

    Start with full access, sending only, or a custom combination of capabilities, projects, and domains.

  2. 02BindSelect its resources

    Keep a runtime inside one project or let a trusted operator work across a selected set.

  3. 03RunLet policy enforce it

    Every API request checks the capability and resource boundary before the operation runs.

  4. 04RotateReplace, then revoke

    Mint the replacement, update the workflow, and delete the old grant without changing the account.

One key per workflow

Keep the blast radius small enough to explain.

Runtime, deploy, agent, and inbound jobs do not need the same authority. Give each one a credential whose purpose is obvious from its name and grant.

AppProduction sender

Dispatch transactional mail from the allowed project and sender domain — nothing more.

email:send
DeployTemplate publisher

Give CI its own credential for publishing template changes without a runtime send grant.

templates:write
AgentAuthorized operator

Size the grant to the agent’s task instead of handing it the keys to the whole workspace.

custom grant
InboundReply processor

Read messages and attachments for the project that owns the receiving domain.

receiving:read

Delegation without escalation

A key can hand off less. Never more.

A grant needs api-keys:write to list key metadata, create credentials, or revoke them. Any credential it creates must fit inside its own capabilities, projects, and domains.

  • Secrets appear only at creation
  • Revocation takes effect immediately
  • Permission failures stop at the boundary
See agent grant rules
Delegated keyAllowed
PParent grantDeployment operatorBroader
api-keys:writetemplates:writeprojects: selected
may create
CChild grantTemplate publisherNarrower
templates:writeproject: Acme App
Privilege cannot expand.A child grant must fit inside every capability and resource boundary carried by its parent.

Ready to scope it?

Give the next workflow exactly one job.

Create the grant, copy its one-time secret into a server-only environment variable, and let the API enforce the boundary.

Create accountOpen API keys
NOTICEAPI

One email API. Every project.

Get API key Read the quickstart

Product

Transactional emailMarketing emailAutomationsTemplatesReceiving APIProjectsPricing

Solutions

AgenciesSaaS teamsIndie buildersAI-assisted buildersCompare Resend

Developers

DocumentationQuickstartAPI referenceNode SDKAgents and MCPReact EmailSimulator

Operate

WebhooksSuppressionsDeliverability autopilotMultiple domainsGuidesTrust centerContact
© 2026 NoticeAPITransactional + marketing email
Acceptable usePrivacyTerms