Works with Klaviyo

Klaviyo sends.Sendfire reads.

Sendfire connects to a brand’s Klaviyo account with a private key that can only read. It reads campaigns, flows, list sizes and results, records when each was read, and never writes to Klaviyo.

What is read
Klaviyoyour account
Sendfireread only
Reading campaigns and messagesnever writes back
Last reviewed 17 Sep 2026Read scopes only · one key per brand

What Sendfire does with a Klaviyo account.

Five statements about how the product is built.

  1. Nothing is written back.

    Klaviyo sends campaigns and runs flows. Sendfire reads what ran and how it did. It never creates, edits, schedules, sends or stops anything in Klaviyo, and the key it uses has no write scope.

  2. One private key, read scopes only.

    Each brand connects with its own private API key, made in Klaviyo with ten read scopes. When the key is connected, Sendfire checks each scope and names any that are missing. The key is encrypted at rest and tied to that Klaviyo account. It can be rotated or revoked, but not moved to a different account.

  3. Klaviyo’s numbers, labelled.

    Every figure is Klaviyo’s, shown with the window it covers and the time it was read. Sendfire does not recompute attribution or add metrics of its own. Where Klaviyo cannot say something, such as which half of a split test received which variation, the row says so.

  4. You keep working in Klaviyo.

    Building, scheduling and sending stay in Klaviyo. Copy written in Sendfire is text you paste into the campaign editor yourself.

  5. Revoking the key stops all reading at once.

    What was already read stays in the brand’s record and is deleted when you ask.

What is read.

The scopes under each group are the ones the key needs for it, as Klaviyo names them.

What you sent

Campaigns, flows and the messages in them.

  • Campaigns and their messages: subject line, preview text, channel, send time
  • The template of a sent campaign, so the email can be shown as it went out
  • Flows, their steps and their messages
  • Tags, to pick which lists and segments to follow

campaigns:readtemplates:readflows:readtags:read

Who it went to

How many people are on each list and segment.

  • List and segment names and their profile counts, recorded each day
  • No profiles. The profiles scope is checked when the key is connected and not used after that

lists:readsegments:readprofiles:read

How it did

Campaign and flow results, as Klaviyo reports them.

  • Campaign and flow results from Klaviyo’s reporting, by day and by window
  • The brand’s conversion metric, chosen at setup
  • No individual orders. The events scope is checked when the key is connected and not used after that

metrics:readevents:readaccounts:read

Not read Billing, account settings, sending domains, and anything else a read scope does not reach.

Whose numbers.

Klaviyo’s. The same figures appear on both sides. Sendfire adds the window each figure covers, the time it was read, and a note where Klaviyo’s data stops.

KlaviyoCampaign report
Alder Shell launch
Delivered
3,877
Opens
1,972
Clicks
195
Placed Order
$6,140
SendfireEvidence
Alder Shell launch
Delivered
3,877
Opens
1,972
Clicks
195
Placed Order
$6,140
7-day attribution · Klaviyo’s window read 17 Sep, 06:04 ET Split not verified
Prepared example, fictional brand. Sendfire adds only the three lines at the bottom.

Day one.

  1. 01

    Make the key in Klaviyo.

    A private API key with the ten read scopes above and nothing else. Klaviyo lists the scopes as checkboxes when the key is created.

  2. 02

    Paste it into the brand.

    Sendfire confirms which Klaviyo account the key belongs to and checks each scope. Missing scopes are named before anything is read.

  3. 03

    The first read.

    The last 180 days of campaigns, every flow, today’s list and segment sizes and 60 days of flow performance. Older campaigns are read afterwards. From then on, campaigns are read three times a day and results each morning.

The steps and the scope list, in Docs

How the key is kept.

The key is encrypted with AES-256-GCM before it is stored and decrypted only in the service that reads Klaviyo. There is one key per brand, tied to one Klaviyo account, and every read is scoped to that brand. Nothing from one brand’s account is visible to another.

If you leave.

Revoke the key in the brand’s settings or delete it in Klaviyo. Reading stops at once. What was read stays in the brand’s record, so past work still shows what it was built on, and is deleted when you ask.

Follow a campaign from brief to review.