Brevo
Connect Brevo as access review source using an API key on the settings page APIKeys andMCP so that the platform can list the users of your account.
The platform reads users of your Brevo account through BrevoAPIso that you can verify who has access.
Prerequisites
Section entitled ‘Prerequisites’- the platform organization administrator access
- The API Keys permission in Brevo, under SMTP & API (the account holder has it; only users with this permission can open the APIKeys &MCPpage and generate a key)
- A key created in your Brevo account that you want to review because a key belongs to exactly one account
Collected Fields
Section entitled “Collected Fields”| the platform field | Brevo field | Notes |
|---|---|---|
| Name | email |
The user’s endpoint does not return any display names, so the platform uses the email address |
email |
||
| Role | feature_access |
Brevo access levels return by feature area (marketing, crm, conversations, transactions, phone and anything else), deduplicated and sorted. A feature set to none is low, so a user with access to nothing has no role |
| Admin | is_owner |
Flagged as administrator when is_owner is true. Brevo returns a boolean, and the platform also supports the string "true" |
| Status | status |
active is listed as an asset and any other value, such as pending, is listed as inactive. |
| MFA | Not supported | |
| Last login | Not supported | |
| External ID | id |
Stable ID used to track your account through reviews. Returns to your email address when the response does not have an ID |
| Created at | Not supported |
The account owner is listed next to all those invited to the account. An invitation that was not accepted but still appears in the list, marked inactive. A user who returned without an email address is omitted.
Step 1: Create an API Key
Section entitled “Step 1: Create anAPIKey”- In Brevo, logged in as an account owner or as a user with API Keys permission, click Download account and select Settings > SMTP & API > API Keys & MCP.
- Click Generate a new API key, name it (for example
Probo Access Review), and set a expiration date from 7 days to 1 year, or choose no expiration. - Click Generate, copy the key (
xkeysib-…) and click on OK. It’s shown only once.
Step 2: Connect in the platform
“Step 2: Connect in the platform”- On the platform, go to Access Reviews > Sources > Add Source.
- Find Brevo, click API KeyPut the key and click Connect.
The user terminal does not return any account names, so the platform lists the source under the fixed name Brevo and attracts the account users into your campaigns.
Troubleshooting
Section “Troubleshooting”- Key rejected. Confirms that it is an API key(
xkeysib-…) from API Keys & MCP A key also ceases to work once it reaches the expiration date, and Brevo expires any key that remains unused for 90 days. - Generate a new API key is unavailable. Only the account owner and users with API Keys permission, under SMTP & API, can open the pageAPIKeys &MCPand create or delete a key.
- Calls stop working after the key has worked once. Brevo can block APIs from unauthorized IP addresses. Settings > Security > Authorized IPs, disable IPAPI-key blocking for ZebraByteCloud. For a self-hosted implementation, you can instead authorize the fixed egress addresses of the implementation.
- Numai proprietarul contului apare. Free and Starter plans include a single user location so that those accounts do not have other users to review. Otherwise, confirm that the key was created in the account whose users you want to review: one key belongs exactly to a Brevo account, and an admin account and each of its sub-organisations have their own keys.