Klaviyo K:BOS 2026: Headless Opens 490 APIs to Claude and ChatGPT
After K:BOS 2026, an agent in a chat window can build a segment, draft the email, and schedule the send, and nobody on your team logs into Klaviyo at any point in that chain. Klaviyo Headless, announced at the Hynes Convention Center in Boston on September 9-10, 2026, exposes more than 260 Model Context Protocol tools and capabilities and more than 490 APIs to Claude, ChatGPT, or any other AI system.
Read, write, launch
The spring release connected Klaviyo data to Claude for reading. An agent could pull flow performance, audit unsubscribe rates, compare segments against benchmarks, and hand you a report. Every change it recommended, a human then made in the interface.
Headless adds the other two verbs. The MCP tool surface accepts writes, so an agent can push changes back into Klaviyo and take a campaign live. With more than 260 tools and capabilities and more than 490 APIs behind them, an agent reaches the whole platform, well past the reporting endpoints the spring release covered.
The gap shows up in a single request. Ask for a win-back campaign targeting openers from the last 60 days who did not buy, and the spring setup returned a segment definition plus copy that an ops person retyped into Klaviyo. The same request now ends with a campaign sitting in the schedule.
For a DTC team that means the transcription work disappears and the review work does not. Somebody still decides whether the send is a good idea, checks the audience size, and reads the copy before it goes out to a list of a few hundred thousand.
The second-order change is who can ask. Because the entry point is now whatever AI tool your team already uses, people who never learned the Klaviyo interface can make requests directly. A product manager wanting email performance on one SKU no longer waits in a queue behind the lifecycle marketer. More people get answers faster, and more people can reach production data, which is the half you have to handle with key scopes and permissions.
What else shipped
| Release | Status | What it is |
|---|---|---|
| Headless | Launched | 260+ MCP tools and capabilities, 490+ APIs open to external AI systems |
| SQL in Klaviyo Data Platform | Preview | Plain-language question translated into a SQL query, reachable via Composer and MCP |
| Customer Agent | Generally available | Klaviyo’s fastest-growing product ever, 40% quarter over quarter |
| Composer | Beta | Used by 138,000 customers |
Klaviyo also changed its own positioning to The Autonomous B2C CRM as of Q3 2026. That label tracks the Headless product line: a CRM that expects an agent at the controls rather than a marketer clicking through screens.
Customer Agent growing 40% quarter over quarter is the number worth planning around. Money is moving toward support automation faster than toward content generation, which is a useful signal when you decide where the next AI budget line goes.
On pricing, third-party reporting indicates Composer remains in beta with credit-based pricing. Confirm the current terms in your own account before you model the cost.
SQL inside the Klaviyo Data Platform
The SQL preview turns a question written in ordinary English into a SQL query against the Klaviyo Data Platform. It reaches profiles, events, segments, lists, and catalogs, and you use it either through Composer or through MCP.
What this replaces is the CSV export. Klaviyo’s reporting screens answer the questions they were designed for, and anything outside that set used to mean exporting data and rebuilding the calculation in a spreadsheet, or writing an API script. A question like “how many customers with two or more orders in the last 90 days opened an email in the last 30 days but clicked nothing” was not expressible in the report builder. It is expressible as SQL.
Treat a preview feature the way you would treat a new analyst. Start with questions whose answers you already know from an existing report, confirm the numbers line up, and only then ask it things you cannot verify. When the generated SQL is visible, read the filters and the date window before you trust the result, because that is where an ambiguous question turns into a wrong number.
Date semantics break more queries than anything else. Whether “the last 30 days” means calendar days or a rolling window, whether “purchased” counts an order placed or a payment captured, these are settled in your head and unstated in your question. Writing the definition into the question costs one clause and saves an hour of reconciliation.
Name the catalogs source explicitly when a question touches products. It lets a single query join product attributes to customer behavior, for example which customers who bought from one category browsed that same category on their most recent session. Questions spanning products and behavior previously meant two exports and a spreadsheet join.
Scoping access before an agent can send
The guardrail question here is different from the one Agent Guidance answers for Customer Agent. That feature governs tone and escalation in support conversations. Headless governs an outbound send, and an outbound send to 200,000 subscribers cannot be recalled.
Six controls to put in place before you connect a production account:
Separate keys by job. Issue one API key per agent use case with only the scopes that use case needs. A reporting agent gets read scopes and nothing else. A campaign-building agent gets write scopes but no delete. One master key wired into everything is how a reporting bug becomes a data loss incident.
Treat draft and send as different privileges. Default every agent to producing drafts. A human clicks send. Reserve full end-to-end authority for narrow, repeatable jobs such as a back-in-stock trigger, with a key scoped to that single flow.
Cap the audience. The classic agent failure is a segment condition written more loosely than intended, turning an 8,000-person send into an 80,000-person send. Check whether a recipient-count ceiling exists on your plan. If it does not, point agents at pre-built segments instead of letting them define audiences at run time.
Keep an audit trail. You need a record of which agent called which endpoint, when, with what parameters. Chat transcripts are not an audit log; they show intent, not the payload that actually hit the API.
Decide who can prompt production. Access control on the Klaviyo side is only half of it. The other half is which people in which workspace can talk to an agent holding a production key. A key scoped correctly still does whatever the person typing asks, so the chat surface itself needs the same access review you would give a Klaviyo user seat.
Run in shadow mode for two weeks. Every agent output becomes a draft, a human reviews each one, and nothing sends. Two weeks of review costs far less than one bad blast, and it tells you exactly which prompts produce audiences you would not have picked yourself.
Who should connect now
Teams already maintaining Klaviyo API scripts have the shortest path. MCP tools replace most of the wrapper code you wrote by hand, and connecting usually reduces the amount of integration you maintain rather than adding to it.
Small stores with a two-person marketing team get less out of it. Your constraint is deciding what to send, not the time it takes to configure a send. Composer addresses that constraint more directly than Headless does.
Brands whose data sits split across Klaviyo, Shopify, and an ad platform are the clearest case for connecting this quarter. Headless plus the SQL preview lets one agent assemble all three views in a single pass, which removes the recurring hours your team spends reconciling numbers by hand.
If you run multiple storefronts, budget for the account structure. Headless connects per Klaviyo account, so five regional accounts mean five sets of keys and five permission configurations to maintain separately.
Related Articles
Converting AI Search Referral Traffic to Email Subscribers: A Retention Playbook
ChatGPT now drives 20% of Walmart referral traffic and over 20% for Etsy. AI-referred visitors have high purchase intent but low brand awareness and rarely return organically. This guide covers email capture strategies, welcome sequences, and retention flows designed specifically for AI referral traffic.
The Personalization Trust Ceiling: 27% of Shoppers Will Not Feed AI Any Data
Braze's 2026 Customer Engagement Review found 27% of consumers refuse to share data with AI agents even for a better experience, while 93% of marketing leaders believe AI understands customers against 53% of consumers. Here is what that gap means for email and CRM strategy.
Customer.io AI Agent vs Klaviyo Marketing Agent: Picking a Single-Prompt Campaign Builder
Klaviyo's Marketing Agent and Customer.io's AI Agent both build full campaigns from one natural-language prompt. This comparison covers data models, credit vs plan-tier pricing, a two-week trial plan, and the guardrails to set before either agent sends.