Kit’s API v4 is the modern REST API for programmatic access to subscribers, tags, forms, sequences, broadcasts, and Kit Commerce. Simple API key authentication, JSON payloads, published rate limits (600 requests per rolling 60 seconds on an OAuth token, 120 on an API key), well-documented webhook subscriptions. What Kit also ships in 2026: two first-party Model Context Protocol servers, documented next to the API itself. Kit MCP lets an AI client act on a creator account; Kit Developer Docs MCP serves these docs to a coding agent. The community wrappers that covered the gap before them still run, but they are no longer the only route.
Model Context Protocol is the emerging standard for connecting LLM agents to external tools. Kit ships two first-party servers for it and documents both: Kit MCP, which acts on a creator account, and Kit Developer Docs MCP, which serves the documentation to a coding agent. The community wrappers listed below predate them and still work.
Kit documents two Model Context Protocol servers of its own. Kit MCP lets an AI client read and write a creator account: it answers at https://app.kit.com/mcp, authenticates by OAuth on the creator behalf, and is “available on all paid Kit plans (Creator and Creator Pro)”. Kit Developer Docs MCP needs no authentication and gives a coding agent live access to the endpoint reference, the OAuth flows and the App Store guidelines. Two community routes predate both and still run: the aplaceforallmystuff/mcp-kit wrapper (self-hosted, covers subscribers, broadcasts and sequences) and Kit MCP via mcpmarket (commercial hosted). Neither is Kit-endorsed, and neither is now required.
Most-active community MCP for Kit. Self-hosted. Manage subscribers, tags, broadcasts, sequences via Claude Desktop natural language.
Commercial hosted Kit MCP. Managed authentication, prompt injection defense, observability layer. Pay-per-use pricing.
Bridge access via Zapier’s MCP layer. Useful if you already run Zapier for other creator tools.
| Base URL | https://api.kit.com/v4 |
|---|---|
| Response format | JSON |
| Authentication | API key (header: X-Kit-Api-Key) or OAuth 2.0 for public apps |
| Rate limits | 600 requests per rolling 60 seconds on an OAuth access token, 120 on an API key |
| Response on rate exceed | HTTP 429. Kit prescribes spacing requests out and exponential backoff, and documents no wait header. |
| Pagination | Cursor-based via after and before query params (max page size 500) |
| Webhook events | Subscriber events (subscribe, unsubscribe, tag added, purchase) |
| Legacy v3 status | Deprecated. Migrate to v4. |
Simplest and most common for internal use. Generate an API key in your Kit account under Account › Settings › Advanced › API. Send it in the request header:
X-Kit-Api-Key: YOUR_API_KEY Content-Type: application/json Accept: application/json
API keys are account-scoped and inherit full account permissions. No granular scopes, a token can do anything the account allows. Rotate keys promptly if compromised.
Required for third-party apps published in the Kit integration marketplace. Standard three-leg authorization code flow. Register your app in the Kit Developer Portal. Access tokens have long lifetimes; no refresh required for most use cases.
| Limit type | Value | Notes |
|---|---|---|
| OAuth access token | 600 per rolling 60 seconds | Published on the response codes page. |
| API key | 120 per rolling 60 seconds | One fifth of the OAuth ceiling, same page. |
| Response on exceed | HTTP 429 | Kit prescribes spacing requests out and exponential backoff. No wait header is documented. |
| Bulk operations | Batch endpoints available for subscriber operations | Preferred over looping single-subscriber calls. |
| Webhook payload size | Not disclosed | Standard SaaS conventions apply. |
The ceiling depends on how you authenticate, which is the part worth planning around: 600 requests per rolling 60 seconds for an OAuth app, 120 for a script holding an API key. A large migration (100K+ subscribers moving in a batch) reaches the API key ceiling long before it reaches the OAuth one. Use the batch endpoints for bulk operations, and back off exponentially on a 429.
| Language | Package | Install | Status |
|---|---|---|---|
| PHP | convertkit/api-client | composer require | Official |
| Node.js | @kit/api-client | npm install | Official |
| Python | Community wrappers | pip install | Community |
| Ruby | Community wrappers | gem install | Community |
Kit’s official SDK footprint is thin (2 official). For Python, Ruby, .NET, and other languages, community wrappers exist but quality varies. Direct API calls with your language’s HTTP client are often safer than an unmaintained community SDK.
| Resource | HTTP methods | Description |
|---|---|---|
| Subscribers /subscribers | GET, POST, PATCH, DELETE | Full CRUD on subscribers. Bulk import via batch endpoints. |
| Tags /tags | GET, POST, PATCH, DELETE | Manage subscriber tags. Add/remove tags on subscribers via tag membership endpoints. |
| Custom fields /custom_fields | GET, POST, PATCH, DELETE | Custom subscriber fields for enrichment (name, phone, custom text). |
| Forms /forms | GET, POST, PATCH | Signup forms and their submissions. Add subscribers via form subscription endpoint. |
| Sequences /sequences | GET, POST | Automated email sequences. Add subscribers to sequences via subscription endpoint. |
| Broadcasts /broadcasts | GET, POST, PATCH, DELETE | One-off newsletter broadcasts. Schedule, send, get reports. |
| Purchases /purchases | GET, POST | Track purchases (from Kit Commerce or external ecommerce). Trigger post-purchase sequences. |
| Webhooks /webhooks | GET, POST, DELETE | Configure webhook subscriptions for subscriber events. |
const axios = require('axios');
const API_KEY = 'YOUR_API_KEY';
const BASE_URL = 'https://api.kit.com/v4';
async function subscribeWithTag(email, tagId) {
// 1. Create subscriber
const created = await axios.post(
`${BASE_URL}/subscribers`,
{
email_address: email,
first_name: 'Alaa',
state: 'active'
},
{ headers: { 'X-Kit-Api-Key': API_KEY } }
);
// 2. Add tag
await axios.post(
`${BASE_URL}/tags/${tagId}/subscribers`,
{ email_address: email },
{ headers: { 'X-Kit-Api-Key': API_KEY } }
);
console.log(`Subscribed and tagged: ${created.data.subscriber.id}`);
}
subscribeWithTag('user@example.com', 'YOUR_TAG_ID');Kit’s legacy API v3 is deprecated. New development targets v4 at api.kit.com/v4. Note that v4 uses X-Kit-Api-Key header (not v3’s api_secret query parameter).
Kit API keys grant full account access. No read-only or object-scoped tokens. For safer third-party integrations, rotate keys on staff turnover and limit key distribution.
You can subscribe/unsubscribe subscribers to existing sequences via the API. Creating or modifying sequence content is UI-only.
Only PHP and Node.js official SDKs. For Python, Ruby, .NET, community wrappers vary in quality. Audit maintenance status before adopting a community SDK, or call the API directly with your language’s HTTP client.
https://app.kit.com/mcp on Creator and Creator Pro, and the public Kit Developer Docs MCP. Community wrappers remain as alternatives.Yes, two. Kit MCP acts on a creator account at https://app.kit.com/mcp over OAuth, on the Creator and Creator Pro plans. Kit Developer Docs MCP serves the developer documentation to a coding agent and needs no authentication. Community alternatives, which predate both: aplaceforallmystuff/mcp-kit (self-hosted, most-active) or Kit MCP via mcpmarket (commercial hosted).
Two officially maintained SDKs: PHP and Node.js. For Python, Ruby, .NET, community wrappers exist but quality varies. Audit maintenance status before adopting a community SDK.
Two limits, both published on the response codes page: 600 requests per rolling 60 seconds on an OAuth access token and 120 on an API key. Past the limit you get an HTTP 429, and Kit tells you to space requests out and back off exponentially rather than read a wait header. Use batch endpoints for bulk operations.
API key in the X-Kit-Api-Key header. Generate under Account › Settings › Advanced › API. Account-scoped, no granular permissions. For public apps: OAuth 2.0 with app registration in Kit Developer Portal.
Deprecated. Migrate to v4 at api.kit.com/v4. Note that v4 uses X-Kit-Api-Key header (v3 used api_secret query parameter).
Yes. The first-party Kit MCP connects at https://app.kit.com/mcp over OAuth on Creator and Creator Pro. Community alternatives: install aplaceforallmystuff/mcp-kit (self-hosted) or subscribe to Kit MCP via mcpmarket. Both let AI agents manage subscribers, tags, broadcasts, sequences through natural language.
No. Sequences are UI-only for creation and content editing. The API lets you subscribe/unsubscribe subscribers to existing sequences, but sequence creation requires the Kit dashboard.
This review follows our email infrastructure testing methodology. We disclose affiliate relationships in our editorial independence policy.