Skip to main content
Telara

Integrations / Klaviyo

Klaviyo logo

Klaviyo

Klaviyo email marketing and customer data platform (CDP) for managing profiles (contacts), lists, segments, campaigns, and flows.

OAuth 2.0
Indexes
Actions

What Telara does

Capability matrix

Before you connect

Prerequisites

A Klaviyo account you can administer.
Owner or admin who can create private API keys.

Vendor setup

Get the credential

1
Open API keys
In Klaviyo, go to Settings → Account → API Keys (Organization → API keys on newer nav).
2
Create a private key
Click Create Private API Key. Name it for Telara. Grant the permissions this page lists from the catalog. Copy it once. Do not use a public key.
3
Paste in Telara
Settings → Integrations → Klaviyo. Paste the private key into the field Telara shows.

Permissions Telara requests

  • accounts:read
    OAuth 2.0
  • profiles:read
    OAuth 2.0
  • lists:read
    OAuth 2.0
  • lists:write
    OAuth 2.0
  • segments:read
    OAuth 2.0
  • campaigns:read
    OAuth 2.0
  • flows:read
    OAuth 2.0

In Telara

Connect in Telara

OAuth 2.0

OAuth 2.0 app connection. Klaviyo requires PKCE S256 and requires every requested scope to be configured in the app's allowlist. The access is scoped to the authorized Klaviyo account.

In Telara, open Settings → Integrations, choose this connector, and click Connect. Telara sends you to the vendor to approve access, then returns you here. You do not create an OAuth app or paste a client secret.

API key

Klaviyo private API key (starts with "pk_"). Create one under Klaviyo Account > Settings > API Keys > Create Private API Key, scoped to at least profiles:read, lists:read, segments:read, campaigns:read, flows:read, and lists:write (needed for add_profile_to_list). Sent as "Authorization: Klaviyo-API-Key <key>" per Klaviyo's Klaviyo-API-Key securityScheme (confirmed against the official spec — this is an apiKey scheme with a literal "Klaviyo-API-Key " prefix, not a bearer token).

In Telara, open Settings → Integrations, choose this connector, and paste the key into the fields Telara shows.

Fields Telara asks for
  • API key

Knowledge

What gets indexed

ResourceCoverage
ListPartial — not every record the vendor holds is synced
SegmentPartial — not every record the vendor holds is synced
CampaignPartial — not every record the vendor holds is synced

Sync

Freshness & sync

ResourceLagDeletions
ListUp to 1 dayRemoved records disappear on the next full sync
SegmentUp to 1 dayRemoved records disappear on the next full sync
CampaignUp to 1 dayRemoved records disappear on the next full sync

Data handling

Permissions & data handling

The scopes above are the permissions this connector requests. They come from the catalog, not from a hand-written page.

Excluded from semantic search: List, Segment, Campaign.

After connect

Verify it worked

After you save, Telara runs a read-only check against the account. The integration shows as connected when that check succeeds.

Honesty

Known limitations

Public keys are client-side and cannot read lists. Telara needs a private key.
Keys scoped away from campaigns/lists connect and then look empty.