Skip to main content

Overview

OneCLI connects AI agents to HeyReach with an API key. Agents can read campaigns, leads, and the unified inbox, add leads to a sequence, and send LinkedIn messages from your connected sender accounts. The gateway injects the key into every request, so your agent never sees it. This suits agents that already research accounts and should act on the reply too: read who answered, then follow up or move them into a campaign. Connecting takes about a minute.

Connect HeyReach

1

Create an API key in HeyReach

In HeyReach, open Settings > Integrations > API Integration and select New API key.
HeyReach Settings showing the API Integration page with the HeyReach API key field, its value hidden, a copy button, and a New API key button.

The workspace API key, under Settings > Integrations > API Integration.

Copy the key right away and paste it into OneCLI. Keys never expire, but New API key invalidates the previous one, so only regenerate when you mean to.
Organization settings carries a separate HeyReach Master API key, which manages workspaces across the whole organization rather than one of them.
HeyReach Organization settings showing the HeyReach Master API key field with its value hidden, a copy button, and a New Master API key button.

The Master API key, under Organization settings. It reaches every workspace.

Prefer a per-workspace key. The master key is broader than an agent needs, and a single connection using it reaches every client’s data at once. Selecting New Master API key invalidates the previous one, so rotating it breaks anything already using it.
2

Paste it in OneCLI

In the OneCLI dashboard, open Connections > HeyReach, paste the key into API key, and select Connect HeyReach.
OneCLI connect window for HeyReach, showing the setup guide link, the API key field with a hint to go to Settings, Integrations, HeyReach API, and the Connect HeyReach button.

The HeyReach connect window in OneCLI.

OneCLI checks the key with HeyReach before saving it, so a wrong key is rejected right away.
A key covers one HeyReach workspace, which is how HeyReach separates clients. If you run outreach for several, create one key per workspace and connect each separately, using the Connection label under Advanced to tell them apart.

What agents can do

HeyReach pages its reads with a POST body rather than a query string, so most reads are POST requests. OneCLI still files them as reads, which means a read-only grant works as you would expect.

Controlling access

Grant the connection to each agent that needs it, and choose per tool what runs freely, what needs approval, and what’s blocked. Outreach reaches real people under your name, so a good default is to let agents read campaigns, leads, and the inbox freely, and put Send a LinkedIn message and Add leads to a campaign behind approval. Adding leads to an active campaign starts messaging them, so it carries the same weight as sending. Pause campaign and Resume campaign change what every sender is doing, so they are worth gating too. Organization rules add guardrails on top. A blocked request never reaches HeyReach. To disconnect, remove the connection in Connections > HeyReach, then invalidate the key in HeyReach under Settings > Integrations > API Integration by selecting New API key.