Docs
CartWatch Brevo Integration
Automatically blocklist flagged bot contacts for email and SMS in Brevo, so fake checkouts stop polluting your campaigns and your abandoned-cart automations.
What the integration does
CartWatch scores every Shopify checkout for bot behavior. With Brevo connected and auto-suppression enabled, each flagged email address that exists in your Brevo account is:
- Blocklisted for email — the contact stops receiving campaigns, automations and transactional marketing sends.
- Blocklisted for SMS — if the contact has a phone number, SMS campaigns stop too.
If a flagged checkout is later updated and scores below the threshold, CartWatch removes both blocklist flags again so the contact is back to normal.
Why blocklist instead of delete?
Brevo does not charge for blocklisted contacts, and Brevo itself recommends keeping them rather than deleting: a blocklisted contact cannot be accidentally re-imported and mailed again, while a deleted one can. So blocklisting stops both the sending and the cost, with nothing irreversible.
Blocklisted contacts still appear in your Brevo account (under Contacts, filtered by blocklisted) so you can always review what CartWatch did and unblock a contact yourself if you disagree.
Connecting
- Install CartWatch from the Shopify App Store if you haven't already.
- In Brevo, open Settings → SMTP & API → API Keys and click Generate a new API key. Name it something like “CartWatch” and copy the key — Brevo only shows it once.
- Open Settings in CartWatch.
- In the Brevo Integration card, paste the key and click Connect Brevo. CartWatch checks the key against your Brevo account before saving it.
- Still in Brevo, open Settings → Security → Authorised IPs. If blocking of unknown IP addresses shows as Activated, click Deactivate blocking. Brevo turns this on automatically for accounts whose API traffic has been stable for 30 days, and CartWatch's servers don't use fixed IP addresses, so with blocking on every suppression is refused. If Brevo emails you “Verify a new IP” after connecting, choose Stop the review of IP addresses rather than authorising the single address — the next call comes from a different one.
Managing the integration
All Brevo-specific settings live in the Brevo Integration card in CartWatch Settings:
- Auto-suppress bots in Brevo — toggle whether flagged checkouts are blocklisted automatically.
- Disconnect Brevo — deletes the stored API key so CartWatch stops touching your account. You can reconnect at any time with the same or a new key.
To remove CartWatch's access on the Brevo side as well, delete the API key you created under Settings → SMTP & API → API Keys in Brevo.
Troubleshooting
- “Brevo rejected this API key” — the key was mistyped, has been deleted in Brevo, or belongs to a different Brevo account. Generate a fresh key and paste it again.
- Nothing is blocklisted and the key was accepted — almost always Brevo's Authorised IPs blocking. Brevo answers CartWatch with “unrecognised IP address” because our servers call from changing Google Cloud addresses. Deactivate the blocking under Settings → Security → Authorised IPs; CartWatch keeps retrying a refused suppression for 24 hours, so recent bots catch up on their own once it's off.
- A contact wasn't blocklisted — suppression applies only to checkouts CartWatch flags as bots after Brevo is connected, and only once the contact actually exists in your Brevo account. If your Shopify store syncs contacts to Brevo on a delay, CartWatch keeps retrying for 24 hours until they appear.
- A cleared checkout's contact is still blocklisted — Brevo will not unblock a contact it blocklisted itself after a hard bounce or a spam complaint. That is Brevo's rule, not CartWatch's; the contact can only be resubscribed through Brevo's own double opt-in flow.
- You deleted the API key in Brevo — every suppression will fail from then on and CartWatch will alert us. Disconnect and reconnect with a new key in CartWatch Settings.