Cherry Seed

Where do I find my Klaviyo API keys?

klaviyo api keys public api key private api key woocommerce klaviyo setup site id javascript tracking

Quick Answer

Navigate to your Klaviyo account, click Settings in the left sidebar, then select API Keys. Two key types exist: the Public API Key is a six-character alphanumeric code used for client-side JavaScript tracking and is safe to expose in your site's source code. The Private API Key is a longer string used for server-side operations like order syncing and list management — this must remain confidential and should only appear in server-side configuration. The WooCommerce Klaviyo plugin requires both keys during setup. The JavaScript tracking snippet requires only the public key. Klaviyo allows generating multiple private keys for different integrations.

Full Answer

Klaviyo maintains two distinct API key types because they serve fundamentally different security contexts.

The Public API Key — sometimes called the Site ID — is the six-character code visible in your Klaviyo JavaScript snippet. It identifies your Klaviyo account when the tracking script sends browsing events from a visitor's browser. Because it executes client-side, anyone can view it in your page source. This is by design — the public key can only write specific event types and cannot read customer data, modify lists, or access account settings.

The Private API Key grants full read-write access to your Klaviyo account through the server-side API. It can export subscriber lists, delete profiles, modify flow configurations, and access revenue data. This key must never appear in client-side code, public repositories, or frontend JavaScript. If compromised, regenerate it immediately from the same Settings > API Keys page.

For WooCommerce integration specifically, the Klaviyo plugin asks for both keys during initial setup. The public key powers on-site tracking. The private key enables server-side order sync — when a WooCommerce order completes, the plugin uses the private key to push order data directly to Klaviyo's API, bypassing the browser entirely. This server-side sync is why Klaviyo still receives purchase data even when a customer's browser blocks JavaScript tracking.

A common mistake is using the private key where the public key belongs, or sharing the private key with contractors who only need to install the tracking snippet. Create separate private keys for each integration that needs one — Klaviyo supports multiple active private keys, making it easy to revoke access for a specific service without disrupting others.

Sources

Programmatic Access

GET https://seresa.io/wp-json/cherry-tree-by-seresa/v1/seeds/608

Cite This Answer

Cherry Tree by Seresa - https://seresa.io/seed/klaviyo-email/klaviyo-woocommerce-integration-klaviyo-api-keys