Connect Resend to Qoren with an API key
Connect Resend with one API key so agents wake when an email bounces, is opened or arrives, and can check what was sent. Sending always waits for you.
On this page
Connect Resend once and your agents can wake when an email is delivered, bounces, is marked as spam, is opened or clicked, or arrives at one of your receiving addresses. Qoren sets up the Resend webhook itself, so there is no URL or signing secret to copy. Agents you give access to can also check the status of what you sent, and draft an email for you to approve before it goes out.
The key stays with Qoren and never reaches an agent's machine. For how connections work in general, see connect your tools with Integrations.
Before you start#
- You are the owner of your Qoren organization. Only the owner connects tools, gives agents access and disconnects.
- You can create API keys in your Resend team, and you are ready to create one with Full access (see below for why).
- Integrations is on for your account. It is still rolling out: if your sidebar has no Integrations under Capabilities, it is not on your account yet.
Make the key#
- In Resend, open API Keys and choose Create API key. Name it Qoren.
- Set Permission to Full access. Resend has only two kinds of key: full access and sending access. A sending access key can only send email, and cannot manage webhooks, which is how Qoren sets up triggers. Qoren refuses a sending access key.
- Create the key and copy it. It starts with
re_, and Resend shows it only once.
Connect it in Qoren#
- In the sidebar, under Capabilities, click Integrations.
- Under Add a tool, click Resend. The Connect Resend dialog shows the same steps as above.
- If your account works for clients, choose who it is for under Which client is this for?. A client's connection can only be used by that client's agents.
- Paste the key into API key.
- Click Check key. Key checked shows the account (the first sending domain of your team), Can read, Can write and Can add webhooks.
- Under What agents may do, choose Read only or Read and write.
- Click Connect.
Screenshots of the dialog are in connect a tool.
What Qoren checks#
- That the key works and has full access, by listing your domains. A sending access key is refused with "This is a sending access key. Qoren needs a Full access key to set up triggers." A key Resend marks as not active is refused too.
- A name for the connection. Resend has no way to say which team a key belongs to, so Qoren names the connection after your team's first sending domain.
- Webhooks you already have. If your team has webhooks, the check says how many and that Qoren adds its own without changing them.
Because Resend does not identify the team, Qoren cannot confirm that a replacement key belongs to the same team. Paste a key from the same team when you use Replace key.
Give an agent access#
No agent can use the connection until you give it access. Open the connection under Connected, pick the agent in Give access to…, choose its level and click Give access. See give an agent access.
Events#
| Event | What it means |
|---|---|
Email sent (email.sent) | Resend accepted an email and handed it to the recipient's mail server. |
Email delivered (email.delivered) | The recipient's mail server accepted the email. |
Delivery delayed (email.delivery_delayed) | Delivery is delayed for now (a full inbox, a busy server). Resend keeps trying. |
Email bounced (email.bounced) | The recipient's server refused the email for good. Resend stops sending to that address. |
Marked as spam (email.complained) | The recipient marked the email as spam. |
Email failed (email.failed) | Resend could not send the email at all, for example because of a quota or a domain problem. |
Email opened (email.opened) | The recipient opened the email. Only when open tracking is on for the domain. |
Link clicked (email.clicked) | The recipient clicked a link in the email. Only when click tracking is on for the domain. |
Email received (email.received) | An email arrived at one of your receiving addresses. Only for domains with receiving turned on in Resend. |
To have one of these wake an agent, open the agent's Triggers tab and add it under From your connected tools. See wake an agent from a connected tool. Sent, delivered and opened happen once per email or more, so for most teams they are busy: a digest suits them. When you pick an event, Qoren estimates how often it happens from your last seven days of sent email; for the delivery, open, click, bounce, spam and failure events the estimate is a lower bound, and for received and delayed email it is unknown.
How the webhook is set up. Qoren registers one Resend webhook per connection for every event, when you add the first trigger, and sends each event on to the triggers that want it. Resend signs every delivery, and Qoren keeps the webhook's signing secret encrypted and checks each one. A delivery Resend retries keeps its id, so an agent never handles one event twice.
What the agent receives. The event, when it happened, and the email's details: sender, recipients, subject, tags, and the bounce, click or failure detail when there is one. For Email received, Resend's webhook carries no message body, so Qoren reads the message for the agent: its text (or HTML when there is no text), the names and types of up to 20 attachments, and the sender authentication results (SPF, DKIM and DMARC). It is all labelled as data from outside; see how events reach the agent.
Tools agents can use#
| Tool | What it does | Changes records | Always asks |
|---|---|---|---|
| Check an email | Read one sent email's status: recipients, subject, when it was sent and its last event. | No | No |
| List recent emails | List the most recent sent emails, newest first, at most 20, without their bodies. | No | No |
| Send an email | Send one plain-text email to one recipient, from a domain verified in Resend. | Yes | Yes |
Send an email always waits on the Approvals page with the exact sender, recipient, subject and text, whatever the agent's autonomy says. It sends to one recipient at a time, never a list. It is also an outbound tool: after an agent reads data from any connection, its outbound sends keep asking for 30 minutes, see outbound sends after a read.
Your agent's own Qoren mailbox is separate from Resend. To give an agent an inbox of its own, see agent email.
Limits and gotchas#
- Full access only. A sending access key is refused, even for a connection agents would only read from, because Qoren needs it to manage its webhook.
- Disabled webhooks. Resend retries a failing delivery for about a day, then disables the webhook. Qoren's daily check turns it back on and replays the deliveries that failed in the meantime, going back at most three days and up to 25 each time it checks. If the webhook was deleted, Qoren creates it again.
- No webhook limit to check. Resend does not document a cap on webhooks, so there is nothing to count up front. If Resend refuses to add Qoren's webhook, the trigger says so and nothing is created.
- Opens and clicks need tracking. Without open or click tracking on the domain in Resend, those events never arrive.
Troubleshooting#
- "This is a sending access key." Create a new key with Full access and paste that.
- "This Resend key is not active." The key was turned off in Resend. Create a new one.
- "Resend did not accept this key." It was deleted or not copied in full. Create a new key.
- The connection says Needs a new key. Resend stopped accepting the key, its triggers are paused, and you got an email. Replace the key and they come back by themselves. See when a connected tool stops working.
- The connection says Needs attention. Qoren could not put its webhook right. Check the team's webhooks in Resend, then click Check again.
Disconnect and delete the key#
- Open the connection under Connected and click Disconnect.
- In Disconnect Resend?, click Disconnect (or Keep it to back out).
Qoren deletes the stored key, removes the webhook it registered, removes every agent's access and pauses the triggers that used Resend. It cannot revoke the key at Resend, so do that too: in Resend, open API Keys and delete the key.
Frequently asked questions#
Why does Qoren need a full access key?
Resend only lets full access keys manage webhooks, and a webhook is how Qoren hears about bounces, opens and received email. Agents never get the key itself, only the three tools on this page.
Can an agent send email through Resend without me?
No. Send an email always waits for a person on the Approvals page, with the exact message shown, whatever the agent's settings say.
Can an agent read the emails I sent?
It can check the status, recipients and subject of sent emails, never their bodies. For received email, the agent gets the message text when a trigger on Email received wakes it.
What happens to my other Resend webhooks?
Nothing. Qoren adds one webhook of its own and never changes webhooks it did not create.