> ## Documentation Index
> Fetch the complete documentation index at: https://onecli.sh/docs/llms.txt
> Use this file to discover all available pages before exploring further.

# HeyReach Integration: LinkedIn Outreach for Agents

> Agents can read HeyReach campaigns, leads, and the unified inbox, and send LinkedIn messages. Connect in a minute with an API key.

## Overview

OneCLI connects AI agents to [HeyReach](https://heyreach.io) with an API key. Agents can read campaigns, leads, and the unified inbox, add leads to a sequence, and send LinkedIn messages from your connected sender accounts. The gateway injects the key into every request, so your agent never sees it.

This suits agents that already research accounts and should act on the reply too: read who answered, then follow up or move them into a campaign.

Connecting takes about a minute.

<a id="self-hosted" style={{ scrollMarginTop: "8rem" }} />

## Connect HeyReach

<Steps>
  <Step title="Create an API key in HeyReach">
    In HeyReach, open **Settings** > **Integrations** > **API Integration** and select **New API key**.

    <Frame caption="The workspace API key, under Settings > Integrations > API Integration.">
      <img src="https://mintcdn.com/chartdbinc/cpyA2JcquhxAtMzR/images/integrations/heyreach/heyreach-api-key.png?fit=max&auto=format&n=cpyA2JcquhxAtMzR&q=85&s=15f63c6b67fab03288f85935fec1ac8d" alt="HeyReach Settings showing the API Integration page with the HeyReach API key field, its value hidden, a copy button, and a New API key button." width="1600" height="310" data-path="images/integrations/heyreach/heyreach-api-key.png" />
    </Frame>

    Copy the key right away and paste it into OneCLI. Keys never expire, but **New API key** invalidates the previous one, so only regenerate when you mean to.

    <Accordion title="Using a Master API key instead">
      **Organization settings** carries a separate **HeyReach Master API key**, which manages workspaces across the whole organization rather than one of them.

      <Frame caption="The Master API key, under Organization settings. It reaches every workspace.">
        <img src="https://mintcdn.com/chartdbinc/cpyA2JcquhxAtMzR/images/integrations/heyreach/heyreach-master-api-key.png?fit=max&auto=format&n=cpyA2JcquhxAtMzR&q=85&s=cfcd2c3754925d7f5795f9eee3b368c2" alt="HeyReach Organization settings showing the HeyReach Master API key field with its value hidden, a copy button, and a New Master API key button." width="1600" height="310" data-path="images/integrations/heyreach/heyreach-master-api-key.png" />
      </Frame>

      Prefer a per-workspace key. The master key is broader than an agent needs, and a single connection using it reaches every client's data at once. Selecting **New Master API key** invalidates the previous one, so rotating it breaks anything already using it.
    </Accordion>
  </Step>

  <Step title="Paste it in OneCLI">
    In the OneCLI dashboard, open **Connections** > **HeyReach**, paste the key into **API key**, and select **Connect HeyReach**.

    <Frame caption="The HeyReach connect window in OneCLI.">
      <img src="https://mintcdn.com/chartdbinc/QJHXmYn_d5kCIzzM/images/integrations/heyreach/onecli-connect-heyreach.png?fit=max&auto=format&n=QJHXmYn_d5kCIzzM&q=85&s=6b9da82ca068c77b0deaa162f0676588" alt="OneCLI connect window for HeyReach, showing the setup guide link, the API key field with a hint to go to Settings, Integrations, HeyReach API, and the Connect HeyReach button." width="1040" height="1400" data-path="images/integrations/heyreach/onecli-connect-heyreach.png" />
    </Frame>

    OneCLI checks the key with HeyReach before saving it, so a wrong key is rejected right away.
  </Step>
</Steps>

<Note>
  A key covers **one HeyReach workspace**, which is how HeyReach separates clients. If you run outreach for several, create one key per workspace and connect each separately, using the **Connection label** under **Advanced** to tell them apart.
</Note>

## What agents can do

| Area | What agents can do |
| - | - |
| **Campaigns** | List campaigns, read one with its sequence, and see the leads in it with their progress |
| **Leads** | Look up a lead by LinkedIn profile URL, and tag leads |
| **Lead lists** | List lists, read the leads in one, create an empty list, and add leads to it |
| **Inbox** | Read unified-inbox conversations and their messages, and send a LinkedIn message |
| **Sender accounts** | List the connected LinkedIn accounts sending the outreach |
| **Stats** | Read campaign and sender performance |
| **Campaign control** | Add leads to a campaign, pause or resume one, and stop outreach to a single lead |

<Note>
  HeyReach pages its reads with a `POST` body rather than a query string, so most reads are POST requests. OneCLI still files them as reads, which means a read-only grant works as you would expect.
</Note>

## Controlling access

[Grant](/docs/guides/agent-access) the connection to each agent that needs it, and choose per tool what runs freely, what needs approval, and what's blocked.

Outreach reaches real people under your name, so a good default is to let agents read campaigns, leads, and the inbox freely, and put **Send a LinkedIn message** and **Add leads to a campaign** behind approval. Adding leads to an active campaign starts messaging them, so it carries the same weight as sending. **Pause campaign** and **Resume campaign** change what every sender is doing, so they are worth gating too.

Organization [rules](/docs/guides/rules) add guardrails on top. A blocked request never reaches HeyReach.

To disconnect, remove the connection in **Connections** > **HeyReach**, then invalidate the key in HeyReach under **Settings** > **Integrations** > **API Integration** by selecting **New API key**.


This documentation is built and hosted on [Mintlify](https://mintlify.com), a developer documentation platform.