Authentication
Tenants generate their own personal access token from Account → API Tokens, then authenticate every request with:Endpoints
The API currently covers websites and reports:See
routes/api.php in your installation for the definitive, current endpoint list — this platform’s roadmap notes the API surface is expected to grow over time.Webhooks
Register your own endpoint URL under Account → Webhook Endpoints to be notified of:report.completedreport.failed
POST to your endpoint, with an X-Webhook-Signature header — an HMAC-SHA256 of the raw request body, keyed by your endpoint’s own secret (shown once when you create the endpoint). Verify this signature before trusting a delivery.
Failed deliveries are automatically retried with backoff — you don’t need to build your own retry logic for transient failures on your end.