Your Instantly API key lives in the Instantly web app under Settings, in the Integrations / API keys area — not inside a campaign or an email account, which is where most people look first. You create it there, copy it once, and paste it into whatever tool needs to read your workspace.
That's the short answer. The rest of this is the practical version: how to generate one, what to use it for, and how to keep it safe when you're handing workspace access to another tool — which matters a lot more when you run several client workspaces than when you run one.
How to find and create the key, step by step
The exact labels shift as Instantly updates its interface, but the path is stable:
- Log into the Instantly app at app.instantly.ai.
- Open Settings (bottom-left account menu).
- Find the Integrations section, then API keys (in the current V2 interface, API access is scoped — you can create keys with specific permissions rather than one all-powerful key).
- Click Create API key, give it a name you'll recognize later (e.g. the tool it's for, or the client), and choose the scope.
- Copy the key immediately. It's typically shown in full only at creation. If you lose it, you don't recover it — you generate a new one.
Name the key for its purpose, not "test" or "key 1." Six months from now, when you're deciding whether a key is safe to revoke, "ColdOps — Acme workspace" tells you everything and "api2" tells you nothing.
What the API key is actually for
The key is how an outside tool reads or acts on your Instantly workspace without you handing over your login. Common uses:
- Reporting and monitoring dashboards that pull campaign and mailbox data so you're not logging in to check.
- Automations (n8n, Make, Zapier) that push leads in or move data out.
- Custom scripts that read analytics for your own spreadsheets.
For most of these — anything that reads your data rather than sends mail — a read-only key is all you should hand over. A monitoring layer like ColdOps, for example, connects each client's Instantly workspace with a read-only key, watches bounce rates, mailbox health, and deliverability across every client, and never needs write access because it isn't sending anything. If a tool asks for more permission than its job requires, that's worth a second look.
Keep the key safe — this matters more at agency scale
An API key is a credential. Treat it like a password, because functionally it is one.
- One key per workspace or client. Don't reuse a single key across every client's Instantly account. Separate keys keep each client's data isolated and let you revoke one without breaking the others — the same reason you keep one workspace per client in the first place.
- Read-only where possible. If the tool only needs to read, don't give it a key that can also modify campaigns.
- Store it encrypted, never in plaintext. Keep keys out of shared docs, Slack messages, and anything a client could see. Any tool you paste it into should encrypt it at rest and never display it back to you in full.
- Rotate on suspicion. If a key might have leaked, revoke it and generate a new one. It takes two minutes and it's cheap insurance.
Key not working? Run these checks
If a tool rejects your key, it's almost always one of these:
- Wrong workspace. If you manage multiple Instantly accounts, confirm the key came from the workspace you're trying to connect.
- Revoked or expired. A key you deleted (or that was rotated) will fail silently. Generate a fresh one.
- Scope too narrow. A read-only key won't work for a tool that needs to write, and vice versa. Match the scope to the job.
- V1 vs V2 mismatch. Instantly's older V1 keys and the current V2 keys aren't interchangeable. Make sure the tool expects the version you're generating.
- Whitespace. A trailing space or line break copied with the key will break authentication. Paste it clean.
If the key is fine but the campaign still looks broken, that's a different problem — the Instantly campaign not sending checklist covers those causes.
Connecting more than one client
Agencies rarely stop at one workspace. When you're connecting several clients to the same reporting or monitoring tool, generate one key per client and label each clearly. It keeps every client's numbers cleanly separated, makes offboarding trivial (revoke that client's key, done), and means a single compromised key never exposes your whole book.
Once every client's key is in, the payoff is seeing all of them in one dashboard instead of fifteen tabs — which is the whole reason to bother with API access in the first place. Find the key, scope it read-only, label it, and you're connected in under a minute per client.
Frequently asked
Where is the API key in Instantly?
How do I create an Instantly API key?
Is it safe to share your Instantly API key with a tool?
Why isn't my Instantly API key working?
Keep reading
Why cold email clients churn (and how to stop it)
Why cold email agencies lose clients: late problem detection, inconsistent reporting and invisible work. What to fix before the next cancellation.
ReadAgency operationsWhite label cold email reporting for agencies
What white label cold email reporting is, what belongs in a client-ready report, and how agencies send branded weekly updates at scale without the busywork.
ReadAgency operationsBest B2B Lead Database for Cold Email (2026)
The best B2B lead databases for cold email in 2026, compared on data accuracy, verified emails, and export limits. Why Apollo is the pick for most agencies.
Read