/api/v1 carries an API key as a bearer token. This page covers creating a key, choosing its scopes, the plan gate, and the errors you get when something is missing.
Send the key
Pass the key in theAuthorization header on every request:
yk_live_ followed by 43 characters. The SDKs read the key from YUNGLE_API_KEY (Python) or take it as apiKey (JavaScript). The CLI reads YUNGLE_API_KEY before anything else.
Create a key
Create keys in Settings → API keys. Give each key a name you will recognize later, such asci-release or crm-sync, and pick its scopes.
- The key is shown once. Yungle stores only a hash of it, so it cannot show it again. If you lose a key, revoke it and create another.
- A key belongs to your own workspace and acts as its owner: its uploads count against that workspace’s storage and its plan decides what it can do. A member of someone else’s workspace cannot create a key for it.
- A key does not expire. It works until you revoke it.
- Revoking is immediate. The key is checked on every request, so the next request with it fails.
Scopes
A scope grants access to one kind of resource. Pick the narrowest set that does the job.
Two rules apply to every scope:
- A
:writescope includes:readof the same resource. Every write returns what it changed, so a separate read scope would not hold anyway.transfers:writealone is enough to send a transfer and read its receipt. - Scopes never cross resources.
transfers:writecannot read contacts.
GET /me, GET /me/referral, POST /links/resolve and GET /imports/{fileId}. A key with no scopes is refused everywhere.
There is no scope for billing, plan changes, workspace members, API keys or account deletion. Those stay in the dashboard. See What the API cannot do.
Free and paid plans
Every account can use the API. What the free plan reaches:
The plan is checked live on every request. If a subscription lapses, the paid endpoints answer
402 from the next request and work again once it is renewed. Nothing needs re-issuing.
A free workspace cannot create a key with collections:write; the dashboard refuses it at creation.
Authentication errors
Errors lists every error code.
Keep keys safe
- Store keys in environment variables or a secrets manager, never in a repository.
- Use one key per integration, so you can revoke one without breaking the others.
- Do not ship a key to a browser or a mobile app. A key acts as your whole workspace, and the API is server-to-server.
- If a key leaks, revoke it first and investigate second.
AI assistants use OAuth instead
When you connect Claude, ChatGPT, Cursor or another assistant tohttps://yungle.co/mcp, you sign in through your browser and approve what the assistant may do. No API key is involved, and emailing recipients is a separate permission you grant on the consent screen. See MCP.
Next steps
Quickstart
Use your key to send a first transfer.
Limits
Rate limits, email budgets and size ceilings.
Errors
Every error code and how to handle it.
MCP
Connect an AI assistant with OAuth.
