lemlist API Review 2026: Endpoints, Limits, Webhooks and MCP

lemlist API review for 2026: what its 189 operations cover, LinkedIn steps by API, rate limits, unsigned webhooks, the MCP server and what to plan around.

Published 12 min read
lemlist API Review 2026: Endpoints, Limits, Webhooks and MCP

The lemlist API is the REST interface to lemlist, the multichannel outreach platform. It lives at api.lemlist.com/api, authenticates with HTTP Basic auth using an empty username and your API key as the password, and its public OpenAPI file lists 189 operations: campaigns, sequences and their steps, leads, activities, webhooks, schedules, mailboxes and lemwarm, the inbox, the lead database, enrichment and lemlist's CRM. The API, the command-line tool and the MCP server are included on every plan, from the Email plan at $69 a month billed monthly. Unlike the APIs of Instantly and Smartlead, it can build LinkedIn, WhatsApp, SMS and call steps, not only emails.

It is the most complete cold outreach platform API we have reviewed, and it has several loose ends. LinkedIn accounts can only be connected through lemlist's Chrome extension, one per seat, so an API cannot connect your users' LinkedIn accounts for them. Leads sent by API load one per call, and the only bulk route imports from a connected CRM filter. Webhooks are not signed. And lemlist's own pages disagree on authentication and event names, and mix three versioning styles. We read lemlist's developer docs and OpenAPI file, its help center, pricing page and terms on 9 October 2026, and worked through what each of those details means for code.

What does the lemlist API cover?

More of the product than any other cold outreach API we have reviewed. The OpenAPI file has 133 paths and 189 operations, grouped like this:

AreaMain endpointsWhat to know
CampaignsPOST /campaigns, POST /campaigns/{id}/start and /pauseA new campaign gets an empty sequence and a default schedule in Europe/Paris time unless you set one
Sequences and stepsPOST /sequences/{id}/steps, PATCH and DELETE on a stepSteps can be email, LinkedIn, WhatsApp, SMS, phone, manual or an API call, with conditions and A/B variants
LeadsPOST /campaigns/{id}/leads/One lead per call, never an update. A lead already in the campaign returns 400
ActivitiesGET /activitiesversion=v2 is mandatory, 100 results per page
WebhooksPOST /hooks, GET /hooks, DELETE /hooks/{id}No update call, 200 per workspace, one registration per URL
InboxPOST /inbox/email, /inbox/linkedin, /inbox/whatsapp, /inbox/smsReplies and one-off messages can be sent over the API
Mailboxes and lemwarmPOST /user/email-accounts, /lemwarm/{id}/startSMTP and IMAP only by API, and Gmail SMTP connections are refused
Lead database and enrichmentPOST /database/people, POST /enrich, POST /v2/enrichments/bulkEnrichment is asynchronous and uses credits: 5 per email found and verified, 20 per phone number
Unsubscribes/v2/unsubscribes/*The legacy unsubscribe routes stop working on 1 November 2026

Sequence steps cover more channels than any other outreach API we have reviewed: linkedinVisit, linkedinInvite, linkedinSend, linkedinInMail, linkedinVoiceNote, follow, like, comment and endorse, plus whatsappMessage, sms, phone, manual tasks, conditional branches and a step that calls an external API. Two exceptions are worth knowing before you build on them. A voice note step is created as a skeleton, without its audio: you record it in the app, upload a file per lead with POST /leads/audio, or use AI mode, where lemlist turns a text script into audio at send time. And branch writes are in closed beta, so they return 403 unless lemlist has enabled the beta for your team.

How do you authenticate and make a first call?

With HTTP Basic authentication: the username is empty and the password is your API key, so curl takes --user ":YourApiKey". lemlist's authentication page says plainly that the API uses Basic, not Bearer. Its help center, however, describes a Bearer token method, and the old documentation still on GitHub describes an access_token query parameter. Use Basic, since it is what the current docs and the OpenAPI file define.

Keys are generated in the app's settings, under Integrations, shown once, and can be named, so each integration gets its own key and its own last-used date. A key belongs to the user who created it and resolves to exactly one team. An agency running several client teams generates one key per team, and lemlist's MCP page tells you to scope the API key itself, but no lemlist page we found explains how. lemlist's API reference says a request with no key returns 400 with a plain-text message, although its errors page lists 401 for missing authentication.

Adding a lead to a campaign, trimmed from the sample in lemlist's API reference:

Add a lead to a campaign (adapted from lemlist's API reference sample)
curl --request POST \
  --url https://api.lemlist.com/api/campaigns/{campaignId}/leads/ \
  --user ":$LEMLIST_API_KEY" \
  --header 'Content-Type: application/json' \
  --data '
{
  "email": "support@lemlist.com",
  "firstName": "John",
  "lastName": "Doe",
  "companyName": "lemlist",
  "linkedinUrl": "https://www.linkedin.com/in/johndoe",
  "customVariable1": "any value you want"
}
'

Any extra field becomes a custom variable for the sequence. The call creates a lead and never updates one: sending the same contact again returns 400 LEAD_ALREADY_IN_CAMPAIGN, and the deduplicate flag, off by default, also refuses a contact that sits in another campaign. Query parameters can ask lemlist to find and verify the email, find a phone number or enrich from LinkedIn as the lead is added, each using credits.

Three behaviours catch people out in the first week. Some endpoints still default to version 1 of the API, which lemlist calls deprecated, so pass version=v2 wherever the reference mentions it, while other v2 routes put the version in the path instead. A plain DELETE on a lead does not delete it: lemlist's reference says it just unsubscribes the lead unless you pass the remove action. And since 30 March 2026, a contact who unsubscribes fires entityUnsubscribed or variableUnsubscribed rather than emailsUnsubscribed, which now fires only when a lead is stopped by the unsubscribe list, so older webhook handlers miss unsubscribes silently.

What are the lemlist API rate limits?

20 requests per 2 seconds, applied to every route and counted for each API key separately, according to lemlist's rate limit page. Every response carries Retry-After and X-RateLimit headers, and a request over the limit returns 429. One header needs care: X-RateLimit-Reset is a human-readable date string such as "Tue Feb 16 2021 09:02:42 GMT+0100", not a timestamp, so code that parses it as a number breaks. Read Retry-After instead. Bulk enrichment has no separate quota, and lemlist's terms add that API calls must stay at a reasonable volume.

The limit matters most for imports, because leads sent by API load one per call, apart from imports from a connected HubSpot, Salesforce or Pipedrive filter. lemlist's help center says each lead needs its own API call and a campaign holds up to 40,000 leads through the API. At 10 requests a second, filling one campaign takes about 67 minutes of calls on one key, before any enrichment. Pagination is also uneven across the API: campaigns and activities page by offset with up to 100 results, campaign leads go up to 500 but document no offset, the inbox pages by page number, and the lead database by page and size.

How do lemlist webhooks work?

You register a URL with POST /hooks, optionally for one event type and one campaign, and lemlist posts the event as JSON. Leaving the type out subscribes the URL to every event. The OpenAPI file lists 79 event types, covering emails, LinkedIn visits, invitations, messages, follows, endorsements, likes, voice notes and withdrawals with their failures, WhatsApp, SMS, calls, the API step, lead status changes, campaign state, enrichment results and deliverability alerts.

A reply arrives as the activity record. lemlist's published sample carries real-looking personal data, so these are field names from that sample and lemlist's field list, with placeholder values, trimmed:

emailsReplied webhook fields (lemlist docs, placeholder values, trimmed)
{
  "_id": "act_...",
  "type": "emailsReplied",
  "createdAt": "2025-11-18T23:11:26.000Z",
  "isFirst": true,
  "subject": "Re: ...",
  "teamId": "tea_...",
  "leadId": "lea_...",
  "campaignId": "cam_...",
  "campaignName": "Campaign name",
  "sequenceStep": 0,
  "sendUserEmail": "sender@example.com",
  "sendUserMailboxId": "usm_...",
  "leadEmail": "lead@example.com",
  "contactId": "ctc_...",
  "text": "...",
  "secret": "your-secret"
}

The secret field is the whole security model. lemlist does not sign deliveries: you set a secret when you create the webhook, lemlist sends it back in the body of every call, and your endpoint compares it. It cannot be changed, so rotating it means deleting the webhook and creating a new one, since there is no update call. A minimal check, in our code:

Python, check a lemlist webhook secret
import hmac
from flask import Flask, request, abort

app = Flask(__name__)
LEMLIST_SECRET = "your-secret"  # set when the webhook was created

@app.post("/hooks/lemlist")
def lemlist_hook():
    event = request.get_json(force=True)
    if not hmac.compare_digest(str(event.get("secret", "")).encode(), LEMLIST_SECRET.encode()):
        abort(401)
    # dedupe on event["_id"]: lemlist publishes no retry or idempotency rules
    return "", 204

Three more rules shape a webhook setup. A workspace holds 200 webhooks at most, and a URL can be registered only once, whatever its event type or campaign, so either register one URL without a type and filter events yourself, or give each subscription its own URL. lemlist publishes no retry policy. And when an endpoint answers 404 or 410, or its host does not resolve, lemlist disables the webhook rather than deleting it, notifies its owner, and leaves it occupying one of the 200 slots until you delete it.

Can the lemlist API run LinkedIn steps?

It can build them, but it cannot connect the LinkedIn accounts that run them. The API creates and edits every LinkedIn step type, adds leads with a LinkedIn URL, sends one-off LinkedIn messages through the inbox endpoint, reads LinkedIn activity and sets each user's daily LinkedIn limits. The account itself is linked through lemlist's Chrome extension: its help center says the extension is required for LinkedIn automation, that each lemlist account can connect a single LinkedIn account, and that only personal profiles are supported. No endpoint connects a LinkedIn account, and LinkedIn steps are not available on the Email plan at all.

For a team automating its own outreach, that is a setup step done once per rep. For a product that wants to run LinkedIn outreach for its own users, it means each of those users needs a lemlist seat and the extension on their browser. Our guide to LinkedIn Chrome extensions explains what that architecture implies for account safety.

What is the lemlist MCP server?

It is lemlist's official remote MCP server, at app.lemlist.com/mcp, over streamable HTTP, included on every plan. It authenticates with OAuth 2.1, where the consent screen asks you to pick one team, or with an API key in an X-API-Key header. lemlist lists Claude, Claude Code, Cursor, ChatGPT and Codex as clients, with ChatGPT's full MCP support limited to its Business, Enterprise and Edu plans.

How many tools it has depends on the page: 40+ on the product page, around 100 in one lemlist blog post, and 70 in the help center's full tool reference, which we counted. Of those 70, the reference marks 35 as asking for your confirmation before they run, and the write tools include sending messages, deleting leads, purchasing domains and provisioning mailboxes. A generic call_api tool reaches any endpoint, running reads at once and asking before writes. lemlist's developer docs add one warning worth repeating: the bucket parameter that narrows which tools the server advertises does not limit what the API key is allowed to do. Some tools also spend credits, on email finding, verification and phone enrichment.

Can you build a product on the lemlist API?

For your own outreach, yes. To serve your own customers, only under a separate agreement. lemlist's terms say a subscriber is not entitled to assign the use of all or part of the services to its own customers, even for free, and set out a separate route for indirect subscribers, who subscribe in their own name on behalf of clients and must separate each client's email traffic into sub-accounts, under specific terms that are not public. lemlist's help center recommends separate teams when clients need isolated data and billing, and each team needs its own subscription and API key. We found no white-label offer on lemlist's site.

Two other clauses matter to builders. The licence is personal and non-transferable. And data from lemlist's lead finder may not be used to build a competing database, product or service. lemlist actively promotes using the API from AI agents, through its MCP server, command-line tool and agent skill file, and we found no clause in its terms that restricts it.

How does the lemlist API compare with the Swarmhit Smart API?

The lemlist API automates a lemlist team, with the most channels of any outreach platform API. The Swarmhit Smart API is outreach infrastructure built to sit under your own product or AI agent, and as far as we know, Swarmhit is the only Smart API provider: one call creates a campaign with its whole sequence, and the engine behind the API handles pacing, rotation across mailboxes and LinkedIn senders, caps and reply detection.

lemlist APISwarmhit Smart API
Built forAutomating your own lemlist team, or client teams under reseller termsPutting outreach inside your product or agent
AuthenticationBasic auth, empty username and API key as passwordBearer API key in the Authorization header
LinkedInSteps built by API, accounts linked through the Chrome extension, one per seatLinkedIn senders run in Swarmhit's cloud, each on a dedicated proxy, with 250+ safeguards
Limits20 requests per 2 seconds per key, one lead per call except imports from a connected CRM filterPer-sender limits enforced on the server, with a 429 that names the cap, the count used and the reset time
WebhooksShared secret returned in the body, no signatureSigned with HMAC-SHA256
PricingEmail plan $69 a month billed monthly for 50,000 emails, Multichannel from $109 per userCold email from $59 a month for 50,000 sends, in beta, with unlimited mailboxes. LinkedIn from $16.90 per sender a month

Cold email on Swarmhit is in beta, opened workspace by workspace, and its pricing may change during the beta. You pay for the emails you send, not for seats or mailboxes. See the Swarmhit cold email API for the details. If you are weighing lemlist as a tool rather than an API, our lemlist review covers its plans and pricing in full and our list of lemlist competitors the alternatives. Our reviews of the Instantly API and the Smartlead API cover the two email-only platforms, and our outreach API comparison the APIs built to sit under a product.

Build outreach into your own product

The Swarmhit Smart API runs LinkedIn and email steps in one campaign, with LinkedIn senders in the cloud on dedicated proxies, per-sender limits on the server and signed webhooks.

Book a call

Cold email in beta from $59 a month for 50,000 sends; LinkedIn from $16.90 per sender a month, tiered down to $6.90.

FAQ

Does lemlist have an API?

Yes. lemlist's REST API, at api.lemlist.com/api, covers campaigns, sequence steps across email, LinkedIn, WhatsApp, SMS and calls, leads, activities, webhooks, the inbox, mailboxes, lemwarm, the lead database, enrichment and its CRM, with 189 operations in its public OpenAPI file. It is included on every lemlist plan, along with an official command-line tool and an MCP server for AI assistants such as Claude and Cursor.

How do I authenticate with the lemlist API?

With HTTP Basic authentication: leave the username empty and use your API key as the password, which in curl is --user ":YourApiKey". lemlist's developer docs say the API uses Basic and not Bearer, although its help center describes a Bearer method. Generate the key in the app's Integrations settings and copy it at once, since lemlist shows it only once. Each key belongs to one user and one team.

What is the lemlist API rate limit?

20 requests per 2 seconds, counted per API key and applied to every route, with a 429 response when you go over. Responses carry Retry-After and X-RateLimit headers, but the reset header is a readable date string rather than a timestamp, so rely on Retry-After. Leads sent by API load one per call, up to 40,000 per campaign, so a full campaign takes over an hour of calls.

Can the lemlist API run LinkedIn outreach?

It can create every LinkedIn step type, from visits and invitations to messages, InMails, voice notes and comments, add leads with LinkedIn URLs and read LinkedIn activity. It cannot connect a LinkedIn account: that happens through lemlist's Chrome extension, with one personal LinkedIn profile per lemlist account, and LinkedIn steps need the Multichannel or Enterprise plan. Voice note audio is recorded in the app, uploaded per lead, or generated from a text script in AI mode.

Does lemlist have an MCP server?

Yes. lemlist runs an official remote MCP server at app.lemlist.com/mcp, included on every plan, which connects with OAuth or an API key. Its help center lists 70 tools across campaigns, leads, enrichment, CRM, inbox, analytics, deliverability and account settings, and half of them ask for confirmation before running. Narrowing the advertised tools does not narrow what the API key can do.

Can I resell lemlist through its API?

Not on a standard subscription. lemlist's terms say subscribers may not assign the use of the services to their own customers, even for free. Agencies that serve clients subscribe as indirect subscribers, under separate specific terms that are not public, and must separate each client's email traffic into sub-accounts. A product that offers outreach to its own users needs that agreement with lemlist first.

Outreach infrastructure built to sit under your product

Campaigns, pacing, mailbox and sender rotation, reply detection and signed webhooks, on LinkedIn and email, behind one API.

Book a call

Cold email in beta from $59 a month for 50,000 sends; LinkedIn from $16.90 per sender a month, tiered down to $6.90.

Alexandre Risser

Written by

Alexandre Risser

Swarmhit

Building Swarmhit. Writes about LinkedIn outreach, multi-sender infrastructure, and outbound that books meetings.

Ready to ship LinkedIn outreach in your product?

Sequencer, senders, inbox and data behind one API. Public pricing per channel, from $16.90 a sender.

Book an integration call→

Keep reading