messages:send:{your-domain}. Use messages:send:all when sending from many domains. For management tasks such as creating a webhook, use a separate full key from Account Settings → API Keys with the needed scopes. See send-only credentials and authentication.
Keep credentials on the server. Use sandbox mode for tests. Reuse a stable, business-event idempotency key only with the exact same payload; use different keys for sandbox and live sends. Check every recipient’s status and return a failure when any item is error; HTTP 202 alone does not mean every recipient was accepted.
For webhooks, verify the raw request bytes using the full secret as the raw UTF-8 HMAC key, including its aha-whsec- or aha-rsec- prefix. Never base64-decode the secret. The AhaSend SDK verifiers handle this. These examples use a 30,000,000-byte webhook body limit; a hosting platform may impose a smaller limit. Acknowledge verified unknown event types with 2xx. See verification and retry policy.
Start with Your Language
Node.js SDK
@ahasend/sdk gives you a typed client, automatic retries, idempotency keys, and webhook adapters for Express, Fastify, and Next.js.Go SDK
ahasend-go gives you a typed client, built-in retries and idempotency, and a Standard Webhooks verifier for any net/http router.Framework Guides
Express
Fastify
NestJS
Next.js
Nuxt
SvelteKit
Hono
Koa
ElysiaJS
Encore.ts
Remix / React Router
Astro
Vite
Gin (Go)
Echo (Go)
Fiber (Go)
chi (Go)
gorilla/mux (Go)
PHP, Python and CMS Guides
WordPress
Drupal
Symfony
Laravel
Django
Flask
Runtimes and Deployment
The SDK runs on Node.js, Deno, Bun, Cloudflare workerd, and Vercel Edge. These guides cover what each platform changes: where secrets live, how deploys work, and what to watch for.Azure Functions (Node.js)
Azure Functions (Python)
Cloud Run Functions (Node.js)
Cloud Run Functions (Python)
AWS Lambda (Python)
Azure Functions (Go)
Cloud Run Functions (Go)
Bun
Deno Deploy
Cloudflare Workers
AWS Lambda (Node.js)
Vercel
Railway
AI Development Tools
AI agents write email code quickly and invent APIs just as quickly. These guides show how to give each tool the verified AhaSend SDK as standing context, then check the result in sandbox mode before it can send anything real.Bolt.new
Claude
Cursor
GitHub Copilot
Lovable
v0
Windsurf
Credentials and Tests
SMTP guides use SMTP credentials. The released WordPress and Drupal integrations use legacy v1 keys; follow their specific setup steps.1
A Verified Sending Domain
The
from address must be on a domain you have verified. See Domain Setup if you have not done this yet.2
An API Key with Send Scope
For v2 API guides, create one in the dashboard with the
messages:send:{your-domain} scope (messages:send:all for sending from many domains), or scope it to a single domain to limit the blast radius if it leaks. The guides read it from AHASEND_API_KEY, alongside AHASEND_ACCOUNT_ID and, for webhooks, AHASEND_WEBHOOK_SECRET.3
Sandbox Mode for Testing
Add
sandbox: true to any send request and the API validates and accepts it without delivering mail. Use sandbox_result to rehearse a bounce or a suppression. See Sandbox Mode.Reference
API Reference
Every endpoint, parameter, and response, including the webhook event payloads.
CLI
Send test messages and forward webhook events to localhost from your terminal while building an integration.
Related Guides
- Before sending: verify a domain and create a send-only key.
- Other ways to send: REST API, SMTP, CLI quickstart, Node.js SDK and Go SDK.
- Request rules: API authentication, scopes, idempotency, errors and rate limits.
- Testing and events: sandbox mode, CLI webhook testing, event payloads, signature verification and delivery retries.
- Data and limits: retention, tracking and plans and feature availability.

