Full Answer
Klaviyo maintains two distinct API key types because they serve fundamentally different security contexts.
The Public API Key — sometimes called the Site ID — is the six-character code visible in your Klaviyo JavaScript snippet. It identifies your Klaviyo account when the tracking script sends browsing events from a visitor's browser. Because it executes client-side, anyone can view it in your page source. This is by design — the public key can only write specific event types and cannot read customer data, modify lists, or access account settings.
The Private API Key grants full read-write access to your Klaviyo account through the server-side API. It can export subscriber lists, delete profiles, modify flow configurations, and access revenue data. This key must never appear in client-side code, public repositories, or frontend JavaScript. If compromised, regenerate it immediately from the same Settings > API Keys page.
For WooCommerce integration specifically, the Klaviyo plugin asks for both keys during initial setup. The public key powers on-site tracking. The private key enables server-side order sync — when a WooCommerce order completes, the plugin uses the private key to push order data directly to Klaviyo's API, bypassing the browser entirely. This server-side sync is why Klaviyo still receives purchase data even when a customer's browser blocks JavaScript tracking.
A common mistake is using the private key where the public key belongs, or sharing the private key with contractors who only need to install the tracking snippet. Create separate private keys for each integration that needs one — Klaviyo supports multiple active private keys, making it easy to revoke access for a specific service without disrupting others.