Set up an OAuth app
This page walks through implementing OAuth 2 so your application can access the Marketing API on behalf of other Mailchimp users. For how the flow works and why it has the steps it does, see OAuth 2.
What you’ll need
- A Mailchimp account
- An API key, if you want to test against your own account first
- A redirect URI for your application, the URL Mailchimp sends users back
to after they authorize your application. It must be reachable by the user’s
browser, but for local development
http://127.0.0.1:3000/...is fine.
Register your application
Registering gives you the client_id and client_secret your server needs.
- Navigate to the Registered Apps page in your Mailchimp account
- Click Register An App
- Fill out the Register An App form
- Click Create
You’ll see the client_id and client_secret at the bottom of the page.
This is the only time you’ll be able to see client_secret, so you’ll need to
copy it and store it securely.
Implement the flow on your server
The sample below handles the whole flow: authenticating the user, exchanging the code for an access token, then making a first authenticated request on their behalf. Pick your language.
The code above completes the flow and produces an access token, then uses it to call the Ping endpoint, a trivial request that confirms the token works. It doesn’t persist anything; in a real application you’d store the access token against your own user record.
The two URLs involved, if you’re implementing this without the sample:
- Redirect the user to
https://login.mailchimp.com/oauth2/authorize?response_type=code&client_id=YOUR_CLIENT_ID&redirect_uri=YOUR_REDIRECT_URI - Exchange the returned
codewith a POST tohttps://login.mailchimp.com/oauth2/token
Rotate a client secret
If your client_secret is exposed, rotate it:
- Navigate to the Registered Apps page in your Mailchimp account.
- Click Edit for the registered app you need to update.
- In the Client secret field, click Rotate.
- On the pop-up modal, type ROTATE and click Rotate Client Secret.
You’ll see a modal with the client_id and the updated client_secret. Update
your application with the new secret; once rotation completes, requests signed
with the old one fail with a 401.
This is the only time you’ll be able to see the updated client_secret, so
you’ll need to copy it and store it securely.
Next steps
- API structure — conventions you’ll hit across the API
- Batch operations — syncing contacts in bulk once you have a token
- Webhooks — keeping your platform in step with changes made in Mailchimp