All help articles
Help centre
CRM & outreach
Updated 22 Jul 2026

Bring your own outreach keys (Email, WhatsApp, SMS)

Send on your own Email, WhatsApp and SMS provider accounts — keys are encrypted per workspace and never shown again, company keys apply to everyone while personal keys override them, and the consent chokepoint is unchanged.

Finocket sends outreach on its own included accounts out of the box — nothing to set up. If you'd rather send from your own provider accounts (your sender identity, your reputation, your provider bill), add your keys under Profile → Outreach sending. Consent checks are unchanged either way.

Which providers are ready today?

  • Email — ready: Resend and ZeptoMail. Each needs an API key/token and a verified from sender or domain at the provider.
  • Email — listed but coming soon: Amazon SES and SendGrid appear in the list, but they are not wired yet. You can't rely on them for sending today; use Resend or ZeptoMail, or the included sender.
  • WhatsApp — ready: Meta Cloud API (phone-number ID + permanent access token) and 360dialog (API key). Business-initiated messages must use a Meta-approved template.
  • SMS — ready: MSG91, Fast2SMS, Twilio and Plivo. Indian routes need a DLT-registered sender ID and template IDs; US routes on Twilio need approved A2P 10DLC registration. Until those are in place, SMS stays queued — it is never fired unregistered.

What's the difference between a company key and a personal key?

A company credential — only the workspace owner can set it — applies to everyone in the workspace. A personal credential, which any member can set, overrides the company one for that member's own sending. Set neither and Finocket's included sending applies. This lets a business run one official sender while a field salesperson sends from their own account.

What does bringing a key change — and what doesn't it?

A key only swaps the transport: the account a message physically leaves from. Everything that decides whether a message may go — consent, suppression, quiet hours, template class, jurisdiction rules — runs exactly as before through the single send checkpoint. Your own key never bypasses compliance.

How are my keys protected?

Every credential is encrypted per workspace before it's stored — plaintext never lands in the database, and a saved key is never shown again. The screen only shows which provider is configured and whether it's verified. To rotate a key, paste a new one over it. When you save, use Save & send test email (email) or Save & verify (WhatsApp/SMS) — only verified credentials are used for real outreach, so a bad key can't silently swallow a campaign.

Related: Email, campaigns and consent, Sending & deliverability.

Frequently asked questions

How much does the WhatsApp Business API cost in India?

Meta charges per conversation, with rates varying by category (marketing conversations cost more than utility ones); BSPs like 360dialog add their own plans. With Finocket you bring your own Meta Cloud API or 360dialog account, so you pay the provider directly at their published rates — no markup.

Do I have to bring my own keys to send campaigns?

No. Finocket's included sending works with zero setup. Bring keys only when you want your own sender identity and deliverability reputation, or your own provider pricing. If a channel has no key, the included transport is used automatically for that channel.

Why is my SMS sitting in 'queued'?

Indian SMS needs your DLT sender ID and template registered; US SMS on Twilio needs approved A2P 10DLC. Until those are configured, Finocket holds the messages as queued rather than sending unregistered traffic that carriers would filter or fine. Complete the registration and queued messages become sendable.

Can I store an Amazon SES or SendGrid key now?

You can save the key, but these two adapters aren't live yet — sending stays on your active provider (or the included sender) until they're enabled. For your own email sending today, use Resend or ZeptoMail.

Can my accountant see or change the keys?

No. Accountants are read-only across the workspace and never see credentials — nobody does after saving, since only the provider name and verified status are displayed. Company keys are owner-only to set; team members can only manage their own personal keys.

Does using my own WhatsApp number let me skip template approval?

No. Any business-initiated WhatsApp message through the official API must use a template Meta has approved, whichever account it sends from. Finocket won't attempt an unapproved template send — that protects your number from being flagged or banned.

Related articles

    Bring your own outreach keys (Email, WhatsApp, SMS) · Finocket