Skip to main content

About Klaviyo

Iru reads account users and their permissions, API keys with their scopes, list and segment metadata, and integration connections from Klaviyo’s API. Authentication uses a private API key created under SettingsAPI keys. Klaviyo private keys are scoped at creation. Grant read-only access to the objects your controls cover. Iru reads metadata only. List and segment names and configuration are collected; the profiles inside them are not.

How It Works

Klaviyo uses a custom authorization scheme: the header value is prefixed with Klaviyo-API-Key, not Bearer. Every request also requires a revision header with an ISO 8601 date that pins the API version. Klaviyo versions its API by dated revisions rather than a path segment, and a request without a valid revision is rejected. Iru sets the revision; you supply only the key. Requests target https://a.klaviyo.com/api. There is no subdomain or account host to configure. The public API key (a short company ID used in client-side subscription calls) is a different credential and will not authenticate here. Official references: Authenticate API requests, API versioning and deprecation policy.

Prerequisites

  • An account role that can manage API keys in Klaviyo.
  • Decide what is in scope. Klaviyo lets you exclude list and segment monitoring, and excluded objects produce no evidence.

Connect Klaviyo to Iru

Complete this tab before you connect the source in Compliance.
1

Sign in to Klaviyo

Sign in to Klaviyo with an account that can manage API keys.
2

Open Settings

Open the account menu in the lower left, then select Settings.
3

Open API keys

Go to API keys.
4

Create a private API key

Select Create private API key.
5

Name and scope the key

Enter a label such as Iru Compliance so you can audit the integration later. Set the key’s access to read-only. Use custom scopes and grant read access only to the objects your compliance program covers. Accounts, Lists, and Segments cover the evidence Iru collects. Do not grant full access or any write scope.
6

Create and copy the key

Create the key and copy the value once while Klaviyo displays it.
Continue on the Iru Compliance tab.

Troubleshooting

Check pop-up blocker settings for the Iru site and try again.
Confirm you created a private key, not a public one. The public key is a short company ID used for client-side calls and will not authenticate a server-to-server request.
The private key was created with custom scopes that exclude them. Klaviyo scopes are fixed at creation. Create a new key with the scopes you need.
Either the key lacks read access to them or list and segment monitoring is out of scope for this connection.
This is expected. Iru collects list and segment metadata, not the profiles within them.

Sources Management

Browse and manage every Compliance source.

Getting Started With Compliance

Frameworks, actions, and Artifacts.

Iru Overview

How Endpoint, Compliance, and Identity fit together.

Artifacts Management

Upload, review, and organize evidence from sources and actions.