> ## Documentation Index
> Fetch the complete documentation index at: https://docs.azvian.com/llms.txt
> Use this file to discover all available pages before exploring further.

# API & Webhooks

> Authenticate with a personal access token, and receive signed webhook events

## Authentication

Tenants generate their own personal access token from **Account → API Tokens**, then authenticate every request with:

```
Authorization: Bearer <token>
```

## Endpoints

The API currently covers lists, subscribers, and campaigns:

| Method | Endpoint                           | Description                              |
| ------ | ---------------------------------- | ---------------------------------------- |
| `GET`  | `/api/user`                        | The authenticated tenant's own user info |
| `GET`  | `/api/v1/lists`                    | List your lists                          |
| `GET`  | `/api/v1/lists/{list}`             | A single list's detail                   |
| `GET`  | `/api/v1/lists/{list}/subscribers` | Subscribers on a list                    |
| `GET`  | `/api/v1/campaigns`                | List your campaigns                      |
| `GET`  | `/api/v1/campaigns/{campaign}`     | A single campaign's detail               |

<Info>See `routes/api.php` in your installation for the definitive, current endpoint list.</Info>

## Webhooks

Register your own endpoint URL under **Account → Webhook Endpoints** to be notified of:

* `subscriber.subscribed`
* `subscriber.unsubscribed`
* `campaign.sent`
* `automation.completed`

Each delivery is a signed JSON `POST` to your endpoint, with an `X-Webhook-Signature` header — an HMAC-SHA256 of the raw request body, keyed by your endpoint's own secret (shown once when you create the endpoint). Verify this signature before trusting a delivery.

Failed deliveries are automatically retried with backoff.
