Authentication
Tenants generate their own personal access token from Account → API Tokens, then authenticate every request with:Endpoints
The API currently covers lists, subscribers, and campaigns:See
routes/api.php in your installation for the definitive, current endpoint list.Webhooks
Register your own endpoint URL under Account → Webhook Endpoints to be notified of:subscriber.subscribedsubscriber.unsubscribedcampaign.sentautomation.completed
POST to your endpoint, with an X-Webhook-Signature header — an HMAC-SHA256 of the raw request body, keyed by your endpoint’s own secret (shown once when you create the endpoint). Verify this signature before trusting a delivery.
Failed deliveries are automatically retried with backoff.