Creator email platform
Kit logo

Kit (ConvertKit) API + MCP (2026): v4 REST and Two First-Party MCP Servers

Last verified Aug 27, 2026

Kit’s API v4 is the modern REST API for programmatic access to subscribers, tags, forms, sequences, broadcasts, and Kit Commerce. Simple API key authentication, JSON payloads, published rate limits (600 requests per rolling 60 seconds on an OAuth token, 120 on an API key), well-documented webhook subscriptions. What Kit also ships in 2026: two first-party Model Context Protocol servers, documented next to the API itself. Kit MCP lets an AI client act on a creator account; Kit Developer Docs MCP serves these docs to a coding agent. The community wrappers that covered the gap before them still run, but they are no longer the only route.

At a glance

v4
Current API version
v3 deprecated, migration path documented
2
Official SDKs
PHP + Node.js; community for others
2
Official MCP servers
Kit MCP and Kit Developer Docs MCP

MCP integration in 2026

Model Context Protocol is the emerging standard for connecting LLM agents to external tools. Kit ships two first-party servers for it and documents both: Kit MCP, which acts on a creator account, and Kit Developer Docs MCP, which serves the documentation to a coding agent. The community wrappers listed below predate them and still work.

!

Two official MCP servers, and the community wrappers that came first

Kit documents two Model Context Protocol servers of its own. Kit MCP lets an AI client read and write a creator account: it answers at https://app.kit.com/mcp, authenticates by OAuth on the creator behalf, and is “available on all paid Kit plans (Creator and Creator Pro)”. Kit Developer Docs MCP needs no authentication and gives a coding agent live access to the endpoint reference, the OAuth flows and the App Store guidelines. Two community routes predate both and still run: the aplaceforallmystuff/mcp-kit wrapper (self-hosted, covers subscribers, broadcasts and sequences) and Kit MCP via mcpmarket (commercial hosted). Neither is Kit-endorsed, and neither is now required.

Community and third-party MCP servers for Kit

API v4 essentials

Base URLhttps://api.kit.com/v4
Response formatJSON
AuthenticationAPI key (header: X-Kit-Api-Key) or OAuth 2.0 for public apps
Rate limits600 requests per rolling 60 seconds on an OAuth access token, 120 on an API key
Response on rate exceedHTTP 429. Kit prescribes spacing requests out and exponential backoff, and documents no wait header.
PaginationCursor-based via after and before query params (max page size 500)
Webhook eventsSubscriber events (subscribe, unsubscribe, tag added, purchase)
Legacy v3 statusDeprecated. Migrate to v4.

Authentication methods

API key (X-Kit-Api-Key header)

Simplest and most common for internal use. Generate an API key in your Kit account under Account › Settings › Advanced › API. Send it in the request header:

X-Kit-Api-Key: YOUR_API_KEY
Content-Type: application/json
Accept: application/json

API keys are account-scoped and inherit full account permissions. No granular scopes, a token can do anything the account allows. Rotate keys promptly if compromised.

OAuth 2.0 (for public apps)

Required for third-party apps published in the Kit integration marketplace. Standard three-leg authorization code flow. Register your app in the Kit Developer Portal. Access tokens have long lifetimes; no refresh required for most use cases.

Rate limits

Limit typeValueNotes
OAuth access token600 per rolling 60 secondsPublished on the response codes page.
API key120 per rolling 60 secondsOne fifth of the OAuth ceiling, same page.
Response on exceedHTTP 429Kit prescribes spacing requests out and exponential backoff. No wait header is documented.
Bulk operationsBatch endpoints available for subscriber operationsPreferred over looping single-subscriber calls.
Webhook payload sizeNot disclosedStandard SaaS conventions apply.

The ceiling depends on how you authenticate, which is the part worth planning around: 600 requests per rolling 60 seconds for an OAuth app, 120 for a script holding an API key. A large migration (100K+ subscribers moving in a batch) reaches the API key ceiling long before it reaches the OAuth one. Use the batch endpoints for bulk operations, and back off exponentially on a 429.

Official SDKs

LanguagePackageInstallStatus
PHPconvertkit/api-clientcomposer requireOfficial
Node.js@kit/api-clientnpm installOfficial
PythonCommunity wrapperspip installCommunity
RubyCommunity wrappersgem installCommunity

Kit’s official SDK footprint is thin (2 official). For Python, Ruby, .NET, and other languages, community wrappers exist but quality varies. Direct API calls with your language’s HTTP client are often safer than an unmaintained community SDK.

Endpoints reference

ResourceHTTP methodsDescription
Subscribers
/subscribers
GET, POST, PATCH, DELETEFull CRUD on subscribers. Bulk import via batch endpoints.
Tags
/tags
GET, POST, PATCH, DELETEManage subscriber tags. Add/remove tags on subscribers via tag membership endpoints.
Custom fields
/custom_fields
GET, POST, PATCH, DELETECustom subscriber fields for enrichment (name, phone, custom text).
Forms
/forms
GET, POST, PATCHSignup forms and their submissions. Add subscribers via form subscription endpoint.
Sequences
/sequences
GET, POSTAutomated email sequences. Add subscribers to sequences via subscription endpoint.
Broadcasts
/broadcasts
GET, POST, PATCH, DELETEOne-off newsletter broadcasts. Schedule, send, get reports.
Purchases
/purchases
GET, POSTTrack purchases (from Kit Commerce or external ecommerce). Trigger post-purchase sequences.
Webhooks
/webhooks
GET, POST, DELETEConfigure webhook subscriptions for subscriber events.

Code examples

Node.js: add subscriber and tag

const axios = require('axios');

const API_KEY = 'YOUR_API_KEY';
const BASE_URL = 'https://api.kit.com/v4';

async function subscribeWithTag(email, tagId) {
  // 1. Create subscriber
  const created = await axios.post(
    `${BASE_URL}/subscribers`,
    {
      email_address: email,
      first_name: 'Alaa',
      state: 'active'
    },
    { headers: { 'X-Kit-Api-Key': API_KEY } }
  );

  // 2. Add tag
  await axios.post(
    `${BASE_URL}/tags/${tagId}/subscribers`,
    { email_address: email },
    { headers: { 'X-Kit-Api-Key': API_KEY } }
  );

  console.log(`Subscribed and tagged: ${created.data.subscriber.id}`);
}

subscribeWithTag('user@example.com', 'YOUR_TAG_ID');

Common gotchas

API v3 deprecated, migrate to v4

Kit’s legacy API v3 is deprecated. New development targets v4 at api.kit.com/v4. Note that v4 uses X-Kit-Api-Key header (not v3’s api_secret query parameter).

Tokens do not have granular scopes

Kit API keys grant full account access. No read-only or object-scoped tokens. For safer third-party integrations, rotate keys on staff turnover and limit key distribution.

Sequences are read-only for CRUD via API

You can subscribe/unsubscribe subscribers to existing sequences via the API. Creating or modifying sequence content is UI-only.

Small SDK footprint

Only PHP and Node.js official SDKs. For Python, Ruby, .NET, community wrappers vary in quality. Audit maintenance status before adopting a community SDK, or call the API directly with your language’s HTTP client.

Deprecations and changelog

  • API v4 is current. Modern REST API with cleaner authentication and better documentation.
  • API v3 deprecated. Legacy integrations should migrate to v4 promptly.
  • Two official MCP servers documented in 2026: Kit MCP at https://app.kit.com/mcp on Creator and Creator Pro, and the public Kit Developer Docs MCP. Community wrappers remain as alternatives.
  • ConvertKit renamed to Kit in 2024. API and product names transitioning; some docs still reference “ConvertKit”.
  • Kit Commerce API endpoints matured in 2024-2025 for programmatic creator commerce integration.

Frequently asked questions

Does Kit have an official MCP server for AI agents?

Yes, two. Kit MCP acts on a creator account at https://app.kit.com/mcp over OAuth, on the Creator and Creator Pro plans. Kit Developer Docs MCP serves the developer documentation to a coding agent and needs no authentication. Community alternatives, which predate both: aplaceforallmystuff/mcp-kit (self-hosted, most-active) or Kit MCP via mcpmarket (commercial hosted).

Which programming languages have official Kit SDKs?

Two officially maintained SDKs: PHP and Node.js. For Python, Ruby, .NET, community wrappers exist but quality varies. Audit maintenance status before adopting a community SDK.

What is the Kit API rate limit?

Two limits, both published on the response codes page: 600 requests per rolling 60 seconds on an OAuth access token and 120 on an API key. Past the limit you get an HTTP 429, and Kit tells you to space requests out and back off exponentially rather than read a wait header. Use batch endpoints for bulk operations.

How do I authenticate with the Kit API?

API key in the X-Kit-Api-Key header. Generate under Account › Settings › Advanced › API. Account-scoped, no granular permissions. For public apps: OAuth 2.0 with app registration in Kit Developer Portal.

Is Kit API v3 still supported?

Deprecated. Migrate to v4 at api.kit.com/v4. Note that v4 uses X-Kit-Api-Key header (v3 used api_secret query parameter).

Can I send emails through Kit from Claude Desktop?

Yes. The first-party Kit MCP connects at https://app.kit.com/mcp over OAuth on Creator and Creator Pro. Community alternatives: install aplaceforallmystuff/mcp-kit (self-hosted) or subscribe to Kit MCP via mcpmarket. Both let AI agents manage subscribers, tags, broadcasts, sequences through natural language.

Can I create sequences via the API?

No. Sequences are UI-only for creation and content editing. The API lets you subscribe/unsubscribe subscribers to existing sequences, but sequence creation requires the Kit dashboard.

Changelog (recent)

  • 2026-09-15 Correction. Kit documents two first-party MCP servers, Kit MCP (app.kit.com/mcp, OAuth, Creator and Creator Pro) and the public Kit Developer Docs MCP. This tab previously stated that no official MCP server existed. Published API rate limits corrected at the same time: 600 requests per rolling 60 seconds on an OAuth token, 120 on an API key.
  • 2026-08-18 API + MCP tab published on SMTPedia. First profile documenting Kit API v4 alongside community MCP coverage (aplaceforallmystuff/mcp-kit, mcpmarket).
  • 2026 Community MCP wrappers for Kit gaining traction (aplaceforallmystuff/mcp-kit most-active). First-party MCP servers not yet documented at that date.
AAlaa Touil RRabeb How we test →

This review follows our email infrastructure testing methodology. We disclose affiliate relationships in our editorial independence policy.