Skip to main content

Authentication

Tenants generate their own personal access token from Account → API Tokens, then authenticate every request with:

Endpoints

The API currently covers lists, subscribers, and campaigns:
See routes/api.php in your installation for the definitive, current endpoint list.

Webhooks

Register your own endpoint URL under Account → Webhook Endpoints to be notified of:
  • subscriber.subscribed
  • subscriber.unsubscribed
  • campaign.sent
  • automation.completed
Each delivery is a signed JSON POST to your endpoint, with an X-Webhook-Signature header — an HMAC-SHA256 of the raw request body, keyed by your endpoint’s own secret (shown once when you create the endpoint). Verify this signature before trusting a delivery. Failed deliveries are automatically retried with backoff.