All help articles
Help centre
CRM & outreach
Updated 19 Jul 2026

Bring your own outreach keys (Email, WhatsApp, SMS)

Send campaigns on your own Email, WhatsApp and SMS accounts — keys encrypted and never shown again, India DLT and WhatsApp templates required, and Finocket's included sending used when no key is set. The consent chokepoint is unchanged.

Finocket sends your outreach on its own included accounts out of the box — you don't have to set up anything. But if you'd rather send on your own Email, WhatsApp or SMS accounts — your sender identity, your deliverability reputation, your provider bill — you can bring your own keys. Open Profile → Outreach sending.

What it changes — and what it doesn't

Bring-your-own keys only swap the transport — the account a message physically leaves from. Everything that decides whether a message may go still runs exactly as before: the single send chokepoint that checks consent, the suppression list and quiet-hours / jurisdiction rules on every message. If you set no key, Finocket's included sending is used, unchanged.

Company key or personal key

A company credential (only the workspace owner can set it) applies to everyone in the workspace. A personal credential — which anyone can set — overrides it just for your own sending. Set neither and the included sending applies.

The providers

  • EmailResend and ZeptoMail are live today; each needs an API key/token and a verified from sender or domain. Amazon SES and SendGrid are listed but not wired yet — you can store the key, but sending stays on the active provider until they're enabled.
  • WhatsAppMeta Cloud API (a phone number ID and a permanent access token) or 360dialog (its API key). Business-initiated WhatsApp messages must use a template that Meta has approved before they can go out.
  • SMSMSG91, Fast2SMS, Twilio and Plivo. India routes are governed by DLT: you need a DLT-registered sender ID, and each message carries a DLT template id. US SMS on Twilio also needs an approved A2P 10DLC.

Your keys are encrypted and never shown again

Every credential is encrypted per workspace before it's stored — the plaintext never lands in the database. For that reason a key is never shown again after you save it; the settings screen only ever shows which provider is configured and whether it's verified, never the secret itself. To change one, paste a new key to replace it.

Prove it works before you rely on it

When you save, use Save & send test email (email) or Save & verify (WhatsApp / SMS) to check the credential against the provider — email sends a real test to your profile address; WhatsApp and SMS validate the credential without sending a message. Only verified credentials are used for real outreach, so a bad key can never silently swallow your campaign.

Related: Email, sequences and consent, Sending & deliverability.

Related articles

    Bring your own outreach keys (Email, WhatsApp, SMS) · Finocket