About Klaviyo
Iru reads account users and their permissions, API keys with their scopes, list and segment metadata, and integration connections from Klaviyo’s API. Authentication uses a private API key created under Settings → API keys. Klaviyo private keys are scoped at creation. Grant read-only access to the objects your controls cover. Iru reads metadata only. List and segment names and configuration are collected; the profiles inside them are not.How It Works
Klaviyo-API-Key, not Bearer. Every request also requires a revision header with an ISO 8601 date that pins the API version. Klaviyo versions its API by dated revisions rather than a path segment, and a request without a valid revision is rejected. Iru sets the revision; you supply only the key.
Requests target https://a.klaviyo.com/api. There is no subdomain or account host to configure. The public API key (a short company ID used in client-side subscription calls) is a different credential and will not authenticate here.
Official references: Authenticate API requests, API versioning and deprecation policy.
Prerequisites
- An account role that can manage API keys in Klaviyo.
- Decide what is in scope. Klaviyo lets you exclude list and segment monitoring, and excluded objects produce no evidence.
Connect Klaviyo to Iru
- Klaviyo
- Iru Compliance
Complete this tab before you connect the source in Compliance.
1
Sign in to Klaviyo
Sign in to Klaviyo with an account that can manage API keys.
2
Open Settings
Open the account menu in the lower left, then select Settings.
3
Open API keys
Go to API keys.
4
Create a private API key
Select Create private API key.
5
Name and scope the key
Enter a label such as Iru Compliance so you can audit the integration later. Set the key’s access to read-only. Use custom scopes and grant read access only to the objects your compliance program covers. Accounts, Lists, and Segments cover the evidence Iru collects. Do not grant full access or any write scope.
6
Create and copy the key
Create the key and copy the value once while Klaviyo displays it.
Continue on the Iru Compliance tab.
Troubleshooting
Nothing opens when you turn the source on
Nothing opens when you turn the source on
Check pop-up blocker settings for the Iru site and try again.
Authentication fails
Authentication fails
Confirm you created a private key, not a public one. The public key is a short company ID used for client-side calls and will not authenticate a server-to-server request.
403 on some objects
403 on some objects
The private key was created with custom scopes that exclude them. Klaviyo scopes are fixed at creation. Create a new key with the scopes you need.
Lists and segments are missing
Lists and segments are missing
Either the key lacks read access to them or list and segment monitoring is out of scope for this connection.
Profile data is not appearing
Profile data is not appearing
This is expected. Iru collects list and segment metadata, not the profiles within them.
Related Articles
Sources Management
Browse and manage every Compliance source.
Getting Started With Compliance
Frameworks, actions, and Artifacts.
Iru Overview
How Endpoint, Compliance, and Identity fit together.
Artifacts Management
Upload, review, and organize evidence from sources and actions.
