Integration API keys in Atomato: where they're used and who can see them

Where Atomato uses the integration keys you connect, who can see them in full, and how to rotate or revoke one.

Atomato saves each integration API key you connect with your store's settings, and shows it in full on the integration's page to anyone who can open Atomato. Use a key made only for Atomato, so you can revoke it on its own.

Integrations are on Enterprise+, and legacy paid plans such as Grow and Pro keep them too.

Where Atomato uses a saved key

The key is kept in Atomato's database, and Atomato's server uses it to call your platform:

  • When you connect or update a key. Atomato checks it first: it reads Klaviyo lists, pings Mailchimp, reads Omnisend contacts and tests that the key can write them, or reads Drip subscribers. SKIO keys are saved without a check.
  • When a shopper finishes a signup. The NotiEmail form sends the shopper's details to Atomato, whose server adds your key and passes the signup on. NotiSMS signups work the same way.
  • When you choose a list. In a NotiEmail campaign's Email Opt-in or SMS Opt-in step, the editor uses the saved key to load your Klaviyo lists or Mailchimp audiences.
  • SKIO. The SKIO API key reads a signed-in shopper's subscription details for campaigns with SKIO rules. For each webhook update from SKIO, Atomato reads that subscription with SKIO API key for backend (optional) if you filled it in. Atomato only reads from SKIO.

Atomato doesn't send your keys to your storefront.

Who can see a saved key

Each integration page shows the whole key in the key field and again after Saved API key. Atomato doesn't mask it. The SKIO page shows both keys this way, and its SKIO Webhook Secret Token (optional) field holds the saved token.

Atomato has no roles of its own, so anyone who can open Atomato in your Shopify admin can open an integration page and see the key. To limit who sees your keys, limit which staff and collaborator accounts can open Atomato, as explained in Set up Atomato for a team or agency.

Use a key made only for Atomato

Don't reuse a key that another app or your team uses, so replacing or revoking it affects nothing else.

The Klaviyo Integration page, opened from its card on Integrations.

Where your platform lets you limit a key's access, give it only the scopes a NotiEmail campaign's connect window lists under Required scopes for this key:

  • Klaviyo: List · Read, List · Write and Profile · Write.
  • Mailchimp: Audiences · Read, Audiences · Write and Contacts · Write.
  • Omnisend: Contacts · Read, Contacts · Write and Tags · Write.
  • Drip: Subscribers · Read, Subscribers · Write and Tags · Write.

Rotate or revoke a key

Replace the key in Atomato before you delete the old one. Signups sent with a deleted key don't reach your platform, and the shopper sees no error.

  1. Create the new key in your platform.
  2. In Atomato, click Integrations in the sidebar, then Manage on the tool. Paste the new key and click Update API key (Update on the SKIO page). If the check of a Klaviyo, Mailchimp, Omnisend or Drip key fails, the old key stays.
  3. For an email platform, sign up once on your store to test the new key.
  4. Delete or revoke the old key in your platform.
Integrations in Atomato. Connected tools show Manage; the rest show Connect or Coming soon.

To stop Atomato using a key, click Disconnect on the integration page, which clears everything saved there, then revoke the key in your platform. Disconnecting affects campaigns that use the tool, so read Update or disconnect an integration first.

Before you downgrade or uninstall

Integration pages are locked on Scale and Free. Saved keys stay in Atomato, but you can't open their pages to update or disconnect them, and active NotiFeed or NotiPop campaigns with SKIO rules keep reading from SKIO with the saved key. Uninstalling doesn't clear keys either: they stay in Atomato's database until Shopify sends its request to erase your store's data.

What Integrations shows on the Free and Scale plans.

Disconnect each integration while you're on Enterprise+, and after you downgrade or uninstall, revoke the keys in Klaviyo, Mailchimp, Omnisend, Drip or SKIO. See what happens to your data when you uninstall.