# Integrations

Rasket on Vercel, Netlify and Cloudflare, and in Zapier and n8n. There is no hosting marketplace listing to install today; there are two routes that work on every one of those hosts.

## No hosting marketplace listing, yet

A one-click Vercel Marketplace integration is deliberately deferred. A native listing is billed through the hosting provider — a second billing system beside the Stripe checkout and portal your plan already uses — and it needs a partner review that only a launched product can pass. Meanwhile, a connectable integration is just an OAuth client, which already works. So until the listing exists, pick one of the two routes below.

## The two routes

- **An API key in the environment.** For your own app, deployed to your own project. Create a key in the dashboard under API keys, store it as a secret environment variable, and send from server code.
- **An OAuth app.** For a product that connects *other people's* Rasket teams — an integration you build and publish. Register it once through `POST /oauth/register` with a fixed redirect URI on your own host, and follow [the OAuth flow](https://www.rasket.com/docs/oauth). Each customer approves it for one team, and can revoke it from Settings → Team → Authorized apps.

> Whichever route, the credential stays on the server. Never put a key or a token in a variable your framework exposes to the browser.

## Vercel

### 1. Create the credential

An API key — ideally `sending_access`, restricted to the one domain this project sends from — or, for an integration, a registered OAuth client.

### 2. Add it to the project

In the project's settings, under environment variables, add `RASKET_API_KEY` as a sensitive variable for the environments that send. Redeploy: variables are read when a deployment is built.

### 3. Send from a route handler or server action

A send, reading the key from the environment:

```text
export async function sendEmail(message) {
  const response = await fetch("https://api.rasket.com/emails", {
    method: "POST",
    headers: {
      Authorization: `Bearer ${process.env.RASKET_API_KEY}`,
      "User-Agent": "acme-billing/1.0",
      "Content-Type": "application/json",
    },
    body: JSON.stringify(message),
  });
  return response.json();
}
```

Send the `User-Agent` yourself — a request with no `User-Agent` is refused.

> Coming soon: the rasket package is not published yet.

## Netlify

### 1. Create the credential

As for Vercel: a narrowly scoped API key, or a registered OAuth client.

### 2. Add it to the site

In the site's configuration, under environment variables, add `RASKET_API_KEY` and mark it secret. Scope it to Functions so it never reaches a build log or the client bundle, then trigger a new deploy.

### 3. Send from a function

In a Netlify Function, `process.env.RASKET_API_KEY` holds the key, and the code above works unchanged.

## Cloudflare

### 1. Create the credential

As above: a narrowly scoped API key, or a registered OAuth client.

### 2. Store it as a Worker secret

Adding the key as a secret:

```text
npx wrangler secret put RASKET_API_KEY
```

On Pages, add it as an encrypted environment variable in the project's settings instead.

### 3. Send from the Worker

A Worker reads secrets from `env`, not `process.env`. Plain `fetch` is the simplest client there — send the `User-Agent` yourself:

Reading the secret inside a Worker:

```text
export default {
  async fetch(request, env) {
    const response = await fetch("https://api.rasket.com/emails", {
      method: "POST",
      headers: {
        Authorization: `Bearer ${env.RASKET_API_KEY}`,
        "User-Agent": "acme-billing/1.0",
        "Content-Type": "application/json",
      },
      body: JSON.stringify(message),
    });
    // …
  },
};
```

## Zapier

To connect Rasket to other apps without code, use the Rasket app for Zapier: send email and templates, add contacts, and start a Zap when an email is delivered, bounces or is opened, when mail arrives, or when a contact is added. It connects with a Full access API key. The [Zapier guide](https://www.rasket.com/docs/integrations/zapier) covers every step.

## n8n

To use Rasket in n8n workflows, install the Rasket nodes: the Rasket node sends email and manages contacts, segments and campaigns, and the Rasket Trigger starts a workflow on Rasket's webhook events. They connect with a Full access API key. The [n8n guide](https://www.rasket.com/docs/integrations/n8n) covers installing them and every operation.

## If you are building the integration

An OAuth app has no client secret to hide, but it does have a registration access token (`rkor_…`), shown once, that can change its redirect URIs or delete it — and deleting a client revokes it on every team that connected it. Keep that token in your own secret store, never in the integration's shipped code.

Ask for the fewest scopes the integration needs; a customer sees each one on the consent screen before approving.
