Keap Is Retiring Its XML-RPC API: Dates, Zapier, and What to Do


Quick answer: Keap is retiring its original XML-RPC API in favor of REST v2, and its own help center currently gives two timelines. An article updated in February 2026 describes a hard shutoff on December 31, 2026, after which XML-RPC endpoints return errors. Articles updated in late August 2026 say instead that XML-RPC "will be deprecated without warranty or support starting March 15, 2027," which reads as an end to support rather than a switch-off. Until Keap's pages agree, plan for the earlier date. That covers custom code, plugins, and zaps built on Keap's legacy Zapier app, which runs on XML-RPC.

Sources: Keap's XML-RPC to REST v2 resource mapping guide (updated August 27, 2026), its earlier XML-RPC sunset notice (updated February 5, 2026), and Move Your Zaps to the New Keap Zapier App (August 27, 2026).

What is Keap's XML-RPC API?

XML-RPC is the original Infusionsoft API. Most integrations written during the Infusionsoft years were built on it, including a lot of custom PHP and older plugins. Keap later added REST APIs, and its developer guide now labels REST v2 as the default, REST v1 as current, and XML-RPC as deprecated. XML-RPC requests go to api.infusionsoft.com/crm/xmlrpc; REST v2 requests go to api.infusionsoft.com/crm/rest/v2.

Which date should you plan around?

The earlier one. The February notice is specific: no functional XML-RPC endpoints after December 31, 2026, and no extensions. The newer articles move the date to March 15, 2027 and talk about support ending rather than endpoints disappearing. Either way the direction is the same. Preparing for December and getting until March costs you nothing; preparing for March and losing your integrations over the holidays costs a great deal.

What doesn't depend on the date: new features and fixes land in REST v2, and anything still calling XML-RPC after the cutoff is running on an API Keap has stopped standing behind.

If your zaps use Keap's legacy Zapier app

This is the part most Keap users will actually feel. Thryv says the legacy Keap app in Zapier "runs on Keap's XML-RPC API," while the new Keap Zapier app is built on REST v2. Moving isn't automatic: you reconnect your Keap account in the new app and rebuild each zap with the same triggers and actions. Thryv says that starting March 15, 2027 it will no longer support or maintain integrations built on the legacy app.

Before rebuilding, list every zap that touches Keap, note what each one does, and turn off anything that hasn't run in months instead of migrating it. A forced rebuild is a good moment to find out which zaps still matter, and whether some of them have outgrown Zapier altogether.

How to tell if your custom integrations are affected

You're probably affected if any of these apply:

  • You have a custom integration, written in-house or by a freelancer, that has talked to Infusionsoft or Keap for years. Search the code for xmlrpc, for api.infusionsoft.com/crm/xmlrpc, or for method names such as ContactService.add and DataService.query.
  • The integration uses one of the older Infusionsoft PHP SDKs.
  • A WordPress plugin, membership site or e-commerce connector has synced with Keap since the Infusionsoft days. Ask the vendor directly which Keap API it uses.

Check a related change while you're in there. Keap's legacy API keys, the single per-account key older integrations used, were scheduled to be revoked in the first quarter of 2025. If an old integration stopped working around then, that's the likely reason. Current integrations authenticate with OAuth 2.0 tokens, a Personal Access Token or a Service Account Key, and those credentials work with REST v1, REST v2 and XML-RPC alike. Updating the key alone doesn't move you off XML-RPC.

What migrating to REST v2 involves

Moving from XML-RPC to REST v2 isn't a find-and-replace. It's the same Keap account underneath, but the shape of every call changes.

  • Requests and responses are JSON over standard HTTP methods instead of XML-encoded procedure calls.
  • Generic calls such as DataService.query against a table become specific endpoints for contacts, tags, orders and so on. Some queries need restructuring because the endpoints filter differently.
  • Authentication is a bearer token in the request header. Service Account Keys suit one business connecting its own systems; OAuth suits apps used by many Keap accounts.
  • Rate limits apply. Keap documents 10 requests per second, 240 per minute and 30,000 per day for Personal Access Tokens and Service Account Keys, so bulk jobs may need batching or a queue.
  • Error handling changes, and the migration is a good moment to add retries and logging where the old code had none.

Keap announced in November 2025 that REST v2 had reached full feature parity with XML-RPC, and it released official SDKs in six languages, PHP among them. It has since said that a small number of XML-RPC endpoints won't be converted directly and published a list of them with suggested alternatives, so check every call you rely on before you commit to a cutover date.

A sensible order: inventory every XML-RPC call the integration makes, map each one to its REST v2 equivalent, flag anything without a clean match, rewrite behind the same internal interface so the rest of your code doesn't change, then run old and new side by side against a test contact before switching. For a typical small integration that's a contained project, not a rebuild.

What to do this quarter

  1. List everything that talks to your Keap account, including zaps, plugins and custom code, and who built each one.
  2. For each one, confirm which API or Zapier app it uses. Ask vendors; search custom code.
  3. Rank them by what breaks if they stop: payments and lead intake first, reporting last.
  4. Move the critical ones first, and aim to have everything off XML-RPC before December 31, 2026.

This is work where it helps to be both a Keap Certified Partner and a PHP developer: half of it is knowing what the Keap account expects, and half is rewriting the code that talks to it. If you'd like the inventory done for you, it fits naturally into a Keap audit.

Frequently Asked Questions

Is Keap shutting down its XML-RPC API?

Keap is retiring it in favor of REST v2. An older Keap help article describes a hard shutoff on December 31, 2026; articles updated in August 2026 say XML-RPC will be deprecated without warranty or support starting March 15, 2027. Until Keap's pages agree, plan for the earlier date.

Will my Keap zaps stop working?

Zaps built on Keap's legacy Zapier app run on XML-RPC. Thryv asks users to reconnect Keap in the new Keap Zapier app, which is built on REST v2, and rebuild each zap, and says it will stop supporting integrations built on the legacy app starting March 15, 2027.

What should I migrate to from Keap XML-RPC?

Keap's REST v2 API. Keap labels REST v2 as its default API and publishes official REST v2 SDKs for PHP, Python, C#, Java, JavaScript and TypeScript.

How do I know if my integration uses XML-RPC?

Search the code for xmlrpc or api.infusionsoft.com/crm/xmlrpc, and for method names such as ContactService.add or DataService.query. For third-party plugins and connectors, ask the vendor which Keap API they use.

Does switching to a Service Account Key fix it?

No. Personal Access Tokens and Service Account Keys replaced the retired legacy API keys, but they work with XML-RPC as well as REST. Changing the credential doesn't change which API your code calls.

Not sure what your Keap integrations run on?

We'll inventory what talks to your Keap account, zaps included, tell you which pieces depend on XML-RPC, and quote the move to REST v2.

Book a 15-minute call →

Have a project in mind?

15-minute call. No sales pitch. We'll tell you straight what's worth building.

Book the call →