The Smartlead API is the REST interface to Smartlead, the cold email platform. It lives at server.smartlead.ai/api/v1, authenticates with an API key passed in the URL's query string, and covers campaigns and their sequences, leads, mailboxes and warmup, replies from the master inbox, analytics, webhooks, client sub-accounts and the Smart Prospect lead finder. The API and webhooks start on the Pro plan at $94 a month, and the $39 Base plan has neither. Smartlead also runs an official MCP server, which it describes as 116+ tools, so assistants such as Claude can operate an account.
It does the job for automating Smartlead campaigns and agency client accounts. The friction is in the details: the key travels in URLs, Smartlead's own pages give three different rate limits, its webhook pages disagree on event names, retries and signing, and its terms forbid resale without written consent while its help center advertises it. We read Smartlead's API documentation, all 257 pages of it, its help center, pricing page, terms of 19 May 2026 and fair use policy on 9 October 2026, and worked out what each of those details means for code.
What does the Smartlead API cover?
Everything you do in Smartlead's campaign builder, split across separate calls for the campaign, its sequence, schedule, settings, mailboxes and leads. The main families, from Smartlead's API reference:
| Area | Main endpoints | What to know |
|---|---|---|
| Campaigns | POST /campaigns/create, then /sequences, /schedule, /settings, /email-accounts and /status | Create accepts only a name and a client id. Sequences cannot change while a campaign is active |
| Leads | POST /campaigns/{id}/leads | Up to 400 leads and 200 custom fields per call. Pause and resume work per lead, and unsubscribe works per campaign or across all campaigns |
| Mailboxes | POST /email-accounts/save for SMTP and IMAP, /save-oauth for Gmail and Outlook tokens | max_email_per_day sets the daily cap. Warmup runs from 1 to 50 emails a day |
| Master inbox | POST /campaigns/{id}/reply-email-thread, POST /master-inbox/inbox-replies | Replying needs the message's email_stats_id. Inbox pages hold 20 messages |
| Analytics | 22 GET /analytics endpoints plus per-campaign statistics | The per-campaign analytics-by-date call takes 30 days at most. Three heavy reporting endpoints allow 10 calls a minute |
| Webhooks | POST /webhook/create, POST /campaigns/{id}/webhooks/retrigger-failed-events | User, client and campaign scopes, and a user-level webhook overrides the others |
| Clients | POST /client/save, client API keys | Sub-accounts for agencies, each with its own keys |
| Smart Prospect | prospect-api.smartlead.ai | Uses credits, and its fetch-contacts call returns HTTP 200 with success false when a limit or credit check fails |
| Single send | POST /send-email/initiate | One transactional email outside any campaign |
Sequence steps created through the API are emails. Smartlead campaigns can also hold LinkedIn steps, which run on connected LinkedIn accounts and appear in sequence analytics, and manual steps, which fire a MANUAL_STEP_REACHED webhook when a lead reaches a task someone has to do by hand, but the API documents no field for creating LinkedIn steps, and its subsequence endpoint says LinkedIn triggers visible in the app are not available through it. The deliverability, mailbox marketplace and dedicated server products have APIs too, on separate hosts, opened through Smartlead's support.
How do you authenticate and launch a campaign with the Smartlead API?
With an api_key query parameter on every request, which Smartlead's authentication page calls the recommended method. POST and PATCH requests can carry the key in the JSON body instead, and the help center states there is no OAuth or Bearer token system. Keys come from the settings area of the app, though four Smartlead pages describe four slightly different paths to it. An account can hold up to 25 named admin keys, the primary admin key can be reset but never revoked, and client keys are limited to one client sub-account. Smartlead documents no read-only or per-resource scopes: an admin key can do everything.
A key in the query string ends up wherever URLs are logged: proxies, load balancers, APM tools, error trackers. Scrub the api_key parameter from those logs on day one, and prefer the body for POST requests.
Launching a campaign takes several calls in order. First the campaign itself, which Smartlead's reference shows like this:
curl -X POST "https://server.smartlead.ai/api/v1/campaigns/create?api_key=YOUR_API_KEY" \
-H "Content-Type: application/json" \
-d '{
"name": "Q1 2024 Cold Outreach"
}'The campaign starts as a draft. You then save its sequence, set its schedule with an IANA timezone, set its settings such as the stop condition, link the mailboxes it sends from, and add leads:
curl -X POST "https://server.smartlead.ai/api/v1/campaigns/123/leads?api_key=YOUR_KEY" \
-H "Content-Type: application/json" \
-d '{
"lead_list": [
{
"email": "john@company.com",
"first_name": "John",
"last_name": "Doe",
"company_name": "ACME Corp",
"custom_fields": {
"job_title": "CEO",
"industry": "SaaS"
}
}
],
"settings": {
"ignore_duplicate_leads_in_other_campaign": false,
"return_lead_ids": true
}
}'The last call starts the campaign, and it is where Smartlead's documentation contradicts itself most. The status reference says to send START and not ACTIVE, while the Python and JavaScript samples on the same page send ACTIVE. The reference uses POST, while Smartlead's llms.txt file and help center say PATCH. The reference lists START, PAUSED, STOPPED and ARCHIVED, and the official command-line tool uses START, PAUSE and STOP. Test the call against your own account before you write a wrapper around it. The schedule body has the same problem in a smaller way, nested under a schedule object in the reference and flat with different field names in the getting-started guide.
What are the Smartlead API rate limits?
It depends on the Smartlead page you read. The rate limit guide gives a Standard tier of 60 requests a minute, 1,000 an hour and bursts of 10 a second, and a Pro tier of 120 a minute, 3,000 an hour and 20 a second, without saying which pricing plan maps to which tier. The help center's API article says you have exceeded the limit at 10 requests per 2 seconds. The API introduction gives no number and says limits vary by plan. The guide calls the limit per key, while the help center's article on multiple keys says creating more admin keys does not increase it. Client keys get their own limit, 60 requests a minute by default.
Two kinds of 429 come back. The plan-wide limit returns JSON with a RATE_LIMIT_EXCEEDED code and a retry_after value in seconds, along with X-RateLimit headers and a Retry-After header. Three heavy endpoints, lead statistics, all lead activities and the domain health metrics, have their own limit of 10 calls per 60 seconds on top, and their 429 is plain text with no headers at all. Smartlead's guide says to fall back to a fixed wait of up to 60 seconds for those. Code that relies on Retry-After gets no wait time from them:
import time, requests
def call(method, url, **kwargs):
for attempt in range(5):
r = requests.request(method, url, timeout=30, **kwargs)
if r.status_code != 429:
return r
try:
err = r.json().get("error", {})
wait = int(err.get("retry_after", 0)) or int(r.headers.get("Retry-After", 60))
except (ValueError, AttributeError):
wait = 60 # endpoint-specific limit: plain-text body, no headers
time.sleep(wait)
raise RuntimeError("still rate limited after 5 attempts")Webhook deliveries do not count against the API limit, which is one more reason to receive replies by webhook rather than by polling an inbox that returns 20 messages a page.
How do Smartlead webhooks work?
You create a webhook with POST /webhook/create, at the level of the whole account, one client or one campaign, and pick events in an event_type_map. A user-level webhook takes priority over client and campaign webhooks for the same event. The events cover sent, first sent, opened, clicked, replied, bounced, unsubscribed, lead category updated, campaign status changed, untracked replies and manual steps, and disconnected mailboxes are configured separately in user settings. A reply arrives like this, from Smartlead's events reference:
{
"event_type": "EMAIL_REPLY",
"from_email": "sender@yourcompany.com",
"subject": "Re: Quick question about Acme Corp",
"to_email": "lead@example.com",
"to_name": "John Doe",
"time_replied": "2025-01-15T11:00:00Z",
"reply_body": "<html>Thanks for reaching out. I'm interested...</html>",
"preview_text": "Thanks for reaching out. I'm interested...",
"campaign_name": "Q1 Outreach",
"campaign_id": 123,
"client_id": 456,
"sequence_number": 1
}The documented example carries no lead id and no email_stats_id, which the reply endpoint requires, so an automated answer to a reply probably needs an extra lookup first. The LEAD_CATEGORY_UPDATED event, by contrast, includes the full conversation history.
Smartlead's webhook pages disagree with each other, and the newer one is the one to follow. The integration guide, rewritten in April 2026, documents an X-Smartlead-Signature header with an HMAC SHA256 of the raw body, but no page says where the signing secret is set or shown, and the create call has no secret field. It describes three retries, at 1, 5 and 30 minutes, after which the event is marked failed and can be retriggered over the API, while the older concept page still says five retries over several hours and then the webhook is disabled. The integration guide adds a rule worth coding around: a 4xx response is treated as permanent and not retried, so return a 5xx when your handler fails for a temporary reason, and Smartlead's help center adds that a 2xx counts as delivered even if you drop the event afterwards. Event names also changed: the reference uses EMAIL_REPLY, the older pages EMAIL_REPLIED, and the campaign webhook endpoint LEAD_REPLIED.
How much does Smartlead cost, and which plan includes the API?
Pro, at $94 a month, is the cheapest plan with the API and webhooks. Smartlead's prices in October 2026, from its pricing page:
| Plan | Monthly | Per month on annual billing | Contacts | Sends a month | Price per 1,000 sends | API and webhooks |
|---|---|---|---|---|---|---|
| Base | $39 | $32.50 | 2,000 | 6,000 | $6.50 | No |
| Pro | $94 | $78.30 | 30,000 | 90,000 | About $1.04 | Yes |
| Unlimited Smart | $174 | $144.50 | Unlimited | 150,000 | $1.16 | Yes |
| Unlimited Prime | $379 | $314.60 | Unlimited | 500,000 | About $0.76 | Yes |
The per-1,000 column is our division, and it shows that Unlimited Smart costs more per email than Pro: what you pay for there is unlimited contacts and 50,000 verified prospect emails a month, not cheaper sending. Smartlead's machine-readable llms.txt file gives Prime 510,000 sends instead of 500,000, and mentions an Enterprise tier above it. In October 2026 the pricing page also advertised 50 percent off the first month on any plan.
Every plan claims unlimited mailboxes and unlimited warmup, with the quality of the warmup pool rising by plan, and warmup emails do not count toward your sends. Smartlead's fair use policy, effective February 2026, still lists mailbox caps under older plan names: 100, 300 and 800. The add-ons a builder is likely to need are client workspaces with white labelling at $29 a month each from Pro, dedicated servers at $39 a server, the SmartDelivery deliverability suite from $49 a month, with API access from its $174 tier up, and mailboxes from Smartlead's own marketplace from $3.99 a month. The free trial lasts 14 days with 2,500 sends and 1,250 contacts, and excludes white labelling. Whether it includes the API is unclear, since one of Smartlead's own blog posts tells trial users to check.
What is the Smartlead MCP server?
It is Smartlead's official Model Context Protocol server, which lets an AI assistant run Smartlead through 116+ tools in six areas, according to Smartlead: campaign management, the lead lifecycle, email accounts, deliverability diagnostics, analytics and webhooks. Those include write actions, such as creating campaigns, pausing them and adding leads. Smartlead calls it free with any paid plan, though it runs on an API key, which Base does not include.
The install Smartlead's help center documents today is a remote server over SSE, added to Claude Desktop's configuration through the mcp-remote package, with the address https://mcp.smartlead.ai/sse?user_api_key=YOUR_API_KEY. That puts the API key in the URL again. Smartlead's help center says the integration works only over SSE for now and only in Claude Desktop, with web support to come. A Smartlead blog post from March 2026 gives a different install, an npm package called @smartlead/mcp-server, which returned a 404 from the npm registry when we checked on 9 October 2026. Smartlead publishes no list of the tools and no source code for the server.
No read-only mode, per-tool permission or confirmation step for destructive tools is documented, and an admin key reaches the whole account. Smartlead does not say whether the MCP server accepts client keys. If it does, a client key limits an agent to one client sub-account, so a wrong tool call cannot touch the rest. Smartlead's command-line tool, @smartlead/cli, version 0.1.0 from March 2026, is more cautious: its delete and remove commands require a --confirm flag, and retrying on 429 is off unless you turn it on.
Can you build a product on the Smartlead API?
Agencies can, within limits, and a software product needs Smartlead's written consent. Smartlead is built for agencies: client sub-accounts see only their own campaigns and mailboxes, and white labelling, at $29 a month per client workspace from Pro and switched on by Smartlead's support, puts the app on your own subdomain. Smartlead's help center says this effectively lets you resell Smartlead with your own billing.
Its terms say something stricter. Without Smartlead's prior written consent, customers must not resell, transfer, distribute or make the service available to third parties, the licence cannot be sublicensed, and only automated tools Smartlead provides may operate the service. The fair use policy repeats the ban on reselling or sharing access without express written consent, and the terms let Smartlead put reasonable restrictions on volume. An agency running white-labelled client workspaces is probably inside what Smartlead intends, but anyone building a product that sends through Smartlead for its own users should get that consent in writing before writing the integration.
How does the Smartlead API compare with the Swarmhit Smart API?
The Smartlead API automates a Smartlead account, its campaigns and its client workspaces. The Swarmhit Smart API is outreach infrastructure built to sit under your own product or AI agent, and as far as we know, Swarmhit is the only Smart API provider: one call creates a campaign with its whole sequence, and the engine behind the API handles pacing, rotation across mailboxes and LinkedIn senders, caps and reply detection.
| Smartlead API | Swarmhit Smart API | |
|---|---|---|
| Built for | Automating your Smartlead account and agency clients | Putting outreach inside your product or agent |
| Authentication | API key in the URL query string or the request body | Bearer API key in the Authorization header |
| Channels | Email steps through the API. LinkedIn steps exist in the app, with no documented API field to create them | LinkedIn steps, and email steps in beta, in one sequence |
| Limits | Per-key or per-account rate limits, depending on the page | Per-sender limits enforced on the server, with a 429 that names the cap, the count used and the reset time |
| Webhooks | HMAC signature documented, signing secret not | Signed with HMAC-SHA256 using the endpoint's secret |
| Pricing | API from Pro at $94 for 90,000 sends | Cold email from $59 for 50,000 sends and $199 for 500,000, in beta, with unlimited mailboxes. LinkedIn from $16.90 per sender a month |
Cold email on Swarmhit is in beta, opened workspace by workspace, and its pricing may change during the beta. You pay for the emails you send, not for mailboxes or contacts, and you can connect your own Google, Microsoft or IMAP mailboxes or buy a domain and mailboxes that arrive connected and warming. See the Swarmhit cold email API for the details. If you are comparing cold email platforms rather than APIs, our reviews of the Instantly API and of cold email software cover the alternatives, and our Instantly alternatives guide prices Smartlead against Instantly. The mailbox side of the question is in our guides to email APIs, Gmail sending limits and Outlook sending limits, and our outreach API comparison covers the APIs built to sit under a product.
Build outreach into your own product
The Swarmhit Smart API runs LinkedIn and email steps in one campaign, with per-sender limits enforced on the server and signed webhooks for every reply.
Cold email in beta from $59 a month for 50,000 sends; LinkedIn from $16.90 per sender a month, tiered down to $6.90.
FAQ
Does Smartlead have an API?
Yes. Smartlead's REST API, at server.smartlead.ai/api/v1, covers campaigns, sequences, leads, mailboxes and warmup, master inbox replies, analytics, webhooks, client sub-accounts and the Smart Prospect lead finder, with separate APIs for its deliverability and mailbox products. It authenticates with an API key in the query string. API access starts on the Pro plan at $94 a month, and Smartlead also offers an official MCP server and a command-line tool.
Which Smartlead plan includes the API?
Pro and above. Smartlead's pricing page says the Base plan at $39 a month does not include the API and webhooks, while Pro at $94, Unlimited Smart at $174 and Unlimited Prime at $379 a month include both, on monthly billing. Whether the 14-day free trial includes API access is unclear, since a Smartlead blog post tells trial users to check. The MCP server, which Smartlead calls free with paid plans, needs an API key too.
How does Smartlead API authentication work?
With an API key passed as the api_key query parameter, which Smartlead recommends, or in the JSON body of POST and PATCH requests. Smartlead documents no header or Bearer authentication. An account can create up to 25 named admin keys with access to everything, plus client keys limited to one client sub-account, and the primary admin key can be reset but not revoked. Because keys travel in URLs, scrub them from your logs.
What is the Smartlead API rate limit?
Smartlead's pages disagree. Its rate limit guide gives 60 requests a minute and 10 a second on its Standard tier, and 120 a minute on its Pro tier, while the help center cites 10 requests per 2 seconds. Three heavy reporting endpoints allow only 10 calls per 60 seconds and return a plain-text 429 without headers. Client keys default to 60 requests a minute. Build in backoff and a fixed 60-second fallback.
Does Smartlead have an MCP server?
Yes. Smartlead runs an official remote MCP server, which it describes as 116+ tools for campaigns, leads, email accounts, deliverability, analytics and webhooks, which Smartlead calls free with paid plans, though it needs an API key and so the Pro plan or above. The documented setup connects Claude Desktop over SSE with the API key in the server URL, and Smartlead's help center says other clients are not supported yet. An npm package named in an earlier Smartlead post was not on npm in October 2026.
How much does Smartlead cost?
Smartlead costs $39 a month on Base, $94 on Pro, $174 on Unlimited Smart and $379 on Unlimited Prime, on monthly billing, or $32.50, $78.30, $144.50 and $314.60 a month on annual billing. The plans include 6,000, 90,000, 150,000 and 500,000 sends a month, with unlimited mailboxes and warmup on all of them. White-labelled client workspaces cost $29 a month each from Pro.




