All skills
resend avatar

/resend

@dcdca08 official
by resendresend/resend-skills193 stars
28

Use when working with the Resend email API — sending transactional emails (single or batch), receiving inbound emails via webhooks, managing email templates, tracking delivery events, managing domains, contacts, broadcasts, webhooks, API keys, automations, events, viewing API request logs, checking account usage and quotas, or setting up the Resend SDK. Always use this skill when the user mentions Resend, even for simple tasks like "send an email with Resend" — the skill contains critical gotchas (idempotency keys, webhook verification, template variable syntax) that prevent common production issues.

Use this Skill: https://skilld.dev/gh/resend/resend-skills/resend

This session only. Nothing lands on disk.

referencesapi-keys.md

≈863 tokens on demand. Your agent reads this file only when SKILL.md points to it.

API Keys

Create, list, update, and delete API keys programmatically. No get endpoint exists.

SDK Methods

Operation Node.js Python
Create resend.apiKeys.create(params) resend.ApiKeys.create(params)
List resend.apiKeys.list(params?) resend.ApiKeys.list()
Update resend.apiKeys.update(id, params) resend.ApiKeys.update(params)
Delete resend.apiKeys.remove(id) resend.ApiKeys.remove(id)

Create Parameters

Required: name

Optional: permission, domainId

  • permission: "full_access" (default) or "sending_access"
  • domainId: only applies when permission is "sending_access" — scopes the key to a single domain
  • name: max 50 characters

Update Parameters

Required: name

Only name can be changed. permission and domainId are fixed at creation — recreate the key to change either.

Examples

Node.js

import { Resend } from 'resend';
const resend = new Resend(process.env.RESEND_API_KEY);

// Create a domain-scoped sending key
const { data, error } = await resend.apiKeys.create({
  name: 'Production Sending Key',
  permission: 'sending_access',
  domainId: 'd_abc123',
});

if (error) {
  console.error(error);
  return;
}

// IMPORTANT: This is the only time the token is returned -- store it now
console.log('API Key:', data.token);  // re_xxxxxxxxx
console.log('Key ID:', data.id);

// List all keys (tokens are NOT included in list response)
const { data: keys, error: listError } = await resend.apiKeys.list();

// Rename a key (only `name` is patchable)
const { data: updated, error: updateError } = await resend.apiKeys.update('api_key_id', {
  name: 'Production Sending Key v2',
});

// Delete a key
const { data: deleted, error: deleteError } = await resend.apiKeys.remove('api_key_id');

Python

import resend

resend.api_key = "re_xxxxxxxxx"

# Create a domain-scoped sending key
key = resend.ApiKeys.create({
    "name": "Production Sending Key",
    "permission": "sending_access",
    "domain_id": "d_abc123",
})

# IMPORTANT: Store the token immediately
print(f"API Key: {key['token']}")

# List all keys
keys = resend.ApiKeys.list()

# Rename a key (only "name" is patchable)
resend.ApiKeys.update({
    "id": "api_key_id",
    "name": "Production Sending Key v2",
})

# Delete a key
resend.ApiKeys.remove("api_key_id")

Common Mistakes

Mistake Fix
Not storing the token on create The token is returned once — store it immediately
Expecting a get endpoint Doesn't exist — list returns metadata only (no tokens)
Trying to update permission or domainId Only name can be patched — recreate the key to change scope
Setting domainId with full_access domainId only applies to sending_access keys
Calling .delete() instead of .remove() Node.js SDK uses .remove() for all delete operations
Ignoring error return Node.js SDK returns { data, error } — always check error
Name over 50 characters name has a 50-character limit

Response Fields

List returns metadata for each key:

Field Type Description
id string API key ID
name string Display name
created_at string Creation timestamp
last_used_at string | null Last time the key was used (null if never used)

Source: SKILL.md on GitHub

1 alert1d5 checks · Risk SAFE
  • Gen Agent Trust Hub1d

    The Resend skill is a comprehensive documentation and code integration package for the Resend email service. It follows security best practices, including mandatory webhook signature verification, environment variable usage for secrets, and idempotency for retry safety. While it exposes a surface for processing inbound emails, it includes explicit guidance on mitigating associated risks.

  • Socket1d

    No alerts

  • Snyk1d

    Risk: MEDIUM · 1 issue

  • Runlayer6mo

    12/23 files flagged

  • ZeroLeaks5mo

    Score: 93/100 · 2 sections analyzed

Signed by skilld at dcdca08. This ties the file your Agent reads to that commit on GitHub. It does not review the instructions.

Last checked against GitHub 2 days ago.

Activeupdated 2 days ago
Other metadata
metadata
{
  "author": "resend",
  "version": "3.13.0",
  "homepage": "https://resend.com/agent-skills",
  "source": "https://github.com/resend/resend-skills",
  "openclaw": {
    "primaryEnv": "RESEND_API_KEY",
    "requires": {
      "env": [
        "RESEND_API_KEY"
      ]
    },
    "envVars": [
      {
        "name": "RESEND_API_KEY",
        "required": true,
        "description": "Resend API key for sending and receiving emails"
      },
      {
        "name": "RESEND_WEBHOOK_SECRET",
        "required": false,
        "description": "Webhook signing secret for verifying event payloads"
      }
    ],
    "links": {
      "repository": "https://github.com/resend/resend-skills",
      "documentation": "https://resend.com/docs/resend-skill"
    }
  }
}
inputs
[
  {
    "name": "RESEND_API_KEY",
    "description": "Resend API key for sending and receiving emails. Get yours at https://resend.com/api-keys",
    "required": true
  },
  {
    "name": "RESEND_WEBHOOK_SECRET",
    "description": "Webhook signing secret for verifying event payloads. Found in the Resend dashboard under Webhooks after creating an endpoint.",
    "required": false
  }
]
references
[
  "sending",
  "receiving.md",
  "templates.md",
  "webhooks.md",
  "domains.md",
  "contacts.md",
  "broadcasts.md",
  "api-keys.md",
  "logs.md",
  "contact-properties.md",
  "segments.md",
  "topics.md",
  "automations.md",
  "events.md",
  "usage.md",
  "installation.md",
  "fetch-all-templates.mjs"
]
  • Python
  • API
  • resend
  • email
  • transactional-email
  • webhooks
  • nodejs
  • templates
  • idempotency

README badge

README badge for resend/resend-skills/resend

Integrates the Resend email API for sending single or batch transactional emails, receiving inbound emails via webhooks, managing templates and domains, and tracking delivery events. Use this skill whenever working with Resend — it includes critical guidance on idempotency keys, webhook verification, template variable syntax, and common production gotchas like batch limitations and SDK error handling patterns.

Generated from the current SKILL.md.

Does this skill support both sending and receiving emails?
Yes. The skill covers transactional sends (single and batch), inbound email reception via webhooks, and email management. Receiving requires domain setup and webhook verification; batch sending does not support attachments or scheduling.
What are idempotency keys and why do I need them?
Idempotency keys prevent duplicate emails when retrying failed requests. Format them as `<event-type>/<entity-id>` (e.g. `welcome-email/user-123`) for single sends and `batch-<event-type>/<batch-id>` for batch sends. Keys expire after 24 hours.
How do I verify webhook signatures from Resend?
Use `resend.webhooks.verify()` with the raw request body and svix headers (`svix-id`, `svix-timestamp`, `svix-signature`). Always verify before processing events — unverified webhooks cannot be trusted.
Does the Node.js SDK throw exceptions for API errors?
No. The SDK returns `{ data, error }` for all API calls. Always check the `error` property explicitly instead of using try/catch for handling API failures.
Can I send batch emails with attachments?
No. Batch sending (`POST /emails/batch`) does not support attachments or scheduling. Use single sends when attachments are required.

Generated from the current SKILL.md. These answers refresh after source changes.