Skip to main content

Base URL

All API requests use the following base URL:

Authentication

Server-to-server endpoints authenticate via Bearer token using your app secret:
User-facing pages (/start, /manage) use signed JWT links generated with signLink(). See Authentication for details.

Endpoints

Response format

All API responses return JSON with Content-Type: application/json. Success responses include an ok: true field plus endpoint-specific data. Error responses return a single error string:

Rate limiting

API endpoints are rate-limited to 60 requests per minute per app. Rate limit information is included in response headers:

HTTP status codes