Docs  /  Workflows  /  Connect a Brand to Klaviyo
Workflow · about 4 minutes

Connect a Brand to Klaviyo

Make a private API key with the ten read scopes, paste it into the Brand, confirm the account and scopes, and know what the first read covers.

Outcome

The Brand is connected to one Klaviyo account through a private API key with read scopes only. Sendfire has confirmed the account and every scope, and the first read is under way. Nothing in the Klaviyo account changes: Sendfire never writes to Klaviyo.

Before you start

  • You need a Klaviyo login that can create private API keys for the account. In Klaviyo this is under Settings, Account, API keys.

  • One Brand connects to one Klaviyo account. Once the account is confirmed it stays fixed for that Brand; the key can be rotated or revoked, but a different account needs a different Brand.

  • The key needs these ten read scopes, and nothing else:

    accounts:read · campaigns:read · flows:read · lists:read · segments:read · tags:read · metrics:read · events:read · profiles:read · templates:read

    Sendfire never asks for a write scope. If the key has one, nothing uses it.

Procedure

  1. Make the key in Klaviyo. On the API keys page, create a private key. Give it a name you will recognise later, such as the Brand’s name and “Sendfire”. Set the access level to custom and tick the ten read scopes listed above. Copy the key; Klaviyo shows it once.

  2. Paste it into the Brand. In Sendfire, open the Brand’s setup and paste the key where it asks. Sendfire confirms the key belongs to a Klaviyo account and shows the account it found.

  3. Check the scopes. Sendfire tries each scope with one small read and reports the result. Scopes Klaviyo refuses are listed as missing, with the message “Your key is verified, but it’s missing these read scopes”. Klaviyo does not let you add scopes to an existing key, so create a new key with the full set, paste it here, and verify again. Scopes Sendfire could not check, because Klaviyo was rate-limited or slow, are listed separately as unconfirmed rather than missing.

  4. Choose the conversion metric. Pick the Klaviyo metric that means a sale for this Brand, usually Placed Order. Campaign and flow results are read against it from Klaviyo’s reporting.

  5. Let the first read run. Verifying the key starts it.

What happens next

The first read covers the last 180 days of campaigns and their messages, every flow with its steps and messages, today’s list and segment sizes, and 60 days of daily flow performance. Aggregate campaign and flow results cover the last 365 days. Older campaigns are read in a later pass once the first Campaign Evidence is in place.

After that, Sendfire keeps reading on a schedule, in Eastern Time: campaigns and their messages three times a day, flows and list sizes early each morning, and campaign and flow results each morning. Each fact carries the time it was read. Sendfire marks flow evidence as stale once its latest covered day is more than seven days old.

Sendfire stores what you sent, the sizes of your lists and segments, and how it did. Results come from Klaviyo’s reporting, counted against the Brand’s conversion metric. Sendfire does not read or store individual orders or profiles. The events and profiles scopes are used only to check access when the key is connected.

When it does not look right

  • “Key invalid” or an authentication error. The key is wrong, has been deleted in Klaviyo, or is a public key. Sendfire accepts private keys only; they start with pk_. Make a new private key and try again.
  • Missing scopes after you added them. Klaviyo applies scope changes to a key immediately, but Sendfire only re-checks when you verify again. Press verify.
  • Unconfirmed scopes. Klaviyo answered slowly or with a rate limit. Wait a minute and verify again; unconfirmed does not mean refused.
  • The account shown is not the one you meant. The key belongs to a different Klaviyo account. Discard it before the account is confirmed and make a key in the right account. Once a Brand’s account is confirmed it cannot be changed.
  • Nothing appears after connecting. The first read takes a while for a large account and runs in order, campaigns first. Come back after the first evidence lands; the Brand’s setup shows the state of each read and lets you retry one that failed.

Leaving

To stop Sendfire reading, revoke the key in the Brand’s settings or delete it in Klaviyo. Reading stops at once. What was already read stays in the Brand’s record so past work still shows what it was built on, and is deleted when you ask.

Last verified · 17 SEPT 2026 Revision 2