Skip to content
Splashify Pro
Email docsEmail

Connected apps (OAuth)

If you build an app that many Splashify Pro Email customers use, do not ask each of them for an API key. Add a Connect Splashify Pro button instead: the customer signs in, sees what your app asks for and clicks Allow, and your server gets a token limited to what they allowed. This is standard OAuth 2.0 with the authorization code flow and PKCE.

The full guide, with every parameter, error and limit, is on docs.splashifypro.com. This page has what is specific to Email apps.

Get a Client ID

Create a free developer account at dev.splashifypro.com. It is separate from your Splashify Pro Email account, and you do not need to be a customer. Click New app, pick Email (email.splashifypro.com), add your redirect URL and permissions, and copy the client secret: we show it once.

URLs

Permissions

Every other route, including send-raw, the IP allowlist, account deletion and CSV exports, is refused with 403 endpoint_not_allowed.

The flow

bash
# 1. Send the customer here
https://email.splashifypro.com/oauth/authorize?response_type=code&client_id=spo_app_XXXX&redirect_uri=https%3A%2F%2Fyourapp.example%2Fsplashify%2Fcallback&scope=email.messages%3Asend%20email.reports%3Aread&state=RANDOM_STATE&code_challenge=CHALLENGE&code_challenge_method=S256

# 2. Swap the code for tokens (server side)
curl -X POST https://api.splashifypro.com/api/v1/oauth/token \
  -u "spo_app_XXXX:spo_cs_YYYY" \
  -d grant_type=authorization_code \
  -d code=spo_ac_ZZZZ \
  -d redirect_uri=https://yourapp.example/splashify/callback \
  -d code_verifier=VERIFIER

# 3. Send an email for the customer
curl -X POST https://api.splashifypro.com/api/v1/partner/email/send \
  -H "Authorization: Bearer spo_at_AAAA" -H "Content-Type: application/json" \
  -d '{"from":"[email protected]","to":["[email protected]"],"subject":"Your order","html_body":"<p>On its way.</p>"}'

# 4. Refresh (save the new refresh_token every time)
curl -X POST https://api.splashifypro.com/api/v1/oauth/token \
  -u "spo_app_XXXX:spo_cs_YYYY" -d grant_type=refresh_token -d refresh_token=spo_rt_BBBB

Access tokens last 1 hour. Refresh tokens rotate on every use: always save the new one.

Good to know

  • Send the token only as Authorization: Bearer spo_at_....
  • Emails your app sends are charged to the customer's wallet, or to their account when it is postpaid, at their normal rates.
  • Until your app is verified it can connect up to 25 accounts, send up to 500 emails a day per account, send each email to one address (to, cc and bcc together), and cannot use send-bulk.
  • If the customer's account has allowed IP addresses, your calls must come from one of them, and IPv6 addresses are refused. List your server IPs on your app so customers can add them.
  • Errors from the token gate use the Email API shape: {"error": "insufficient_scope", "message": "This app was not allowed to do this."}.
  • There are no webhooks to apps yet. Poll Get email status for delivery.

Read the full guide: Connect with Splashify Pro.