Configuration API

Endpoints for organization settings, integrations, email and calls, plan status, and the real-time event stream.

Organization settings

GET/api/org-config

The organization's configuration — terminology, stages, statuses, custom fields, currency, visibility, integrations and feature toggles.

Auth: SessionPermission: settings:read
  • Stored credentials are never returned. Integration passwords and webhook header values come back as __saved__.
  • Send __saved__ back on save to keep the stored credential, or a new value to replace it.
PUT/api/org-config

Update configuration.

Auth: SessionPermission: settings:write

Body

(partial config)objectSend only the sections you are changing.
POST/api/org-config

Reset configuration back to defaults.

Auth: SessionPermission: settings:write
GET/api/settings/contact-secret

The secret your website form uses to submit leads.

Auth: Session

Integrations

GET/api/integrations/status

Connection status and usage for every integration.

Auth: SessionPermission: settings:read
GET/api/email/google/status

Whether Gmail is connected, and for which account.

Auth: Session
GET/api/email/google/auth

Begins connecting a Google account. Redirects to Google.

Auth: Session
GET/api/email/google/callback

Where Google returns after you grant access. Not called directly.

Auth: Session
GET/api/settings/twilio

The current Twilio voice configuration.

Auth: SessionPermission: settings:read
POST/api/settings/twilio

Save the Twilio voice configuration.

Auth: SessionPermission: settings:write
DELETE/api/settings/twilio

Disconnect Twilio.

Auth: SessionPermission: settings:write
POST/api/integrations/twilio/test

Check the Twilio configuration before relying on it.

Auth: SessionPermission: settings:write
POST/api/integrations/custom-sql/test

Check the external database connection and column mapping.

Auth: SessionPermission: settings:write
POST/api/integrations/webhook/test

Send a test delivery to one configured API call.

Auth: SessionPermission: settings:write

Body

idstringThe configured call to test. Omit to test an unsaved draft.
namestringDisplay name.
url*stringThe https endpoint to POST to.
headers{key,value}[]Headers to send. A value of __saved__ means keep the stored one.
bodyTemplate*stringJSON body with {{deal.title}} style placeholders.

Returns. { success, status, attempts, responseBody } — the receiver's status code and a truncated response body.

  • Sends sample values, never a real customer record.
  • Returns 400 with the failure reason when the endpoint rejects the delivery.

Email and calls

POST/api/emailing

Send an email to a contact.

Auth: SessionPermission: email:send

Body

to*stringRecipient address.
subject*stringSubject line.
body*stringMessage body.
attachmentsfile[]Files to attach, each up to 5 MB. Send the request as multipart/form-data to include them.
contactIdstringContact the email is for; its attachments are linked to that contact.
  • Accepts JSON, or multipart/form-data when attaching files.
  • Attachments are kept in Resources, linked to the contact they were sent to.
  • Counts towards your plan's monthly email allowance.
POST/api/calls/initiate

Start a call to a contact.

Auth: SessionPermission: calls:initiate

Body

contactId*stringThe contact to call.
userPhoneNumberstringThe number to connect the call to.
notesstringNotes to store against the call.
GET/api/calls/{callSid}/status

The current status of a call.

Auth: SessionPermission: calls:view
POST/api/twilio/token

A short-lived token that lets the browser place calls.

Auth: SessionPermission: calls:initiate

Provider callbacks

Several endpoints exist purely so the telephony provider can report call, dial and recording status back to the application. They are called by the provider, not by you, and are not part of the public surface.

Plan and billing

GET/api/plan/status

The organization's current plan and trial state.

Auth: Session

Returns. { planSlug, planLabel, locked, trialDays, daysRemaining, orgCreatedAt }

GET/api/billing/plans

The plans available to subscribe to, with their features.

Auth: Session
POST/api/plan/sync-seats

Re-synchronise the organization's seat allowance with its subscription.

Auth: Session

Real-time updates

The application keeps open pages current by subscribing to a server-sent event stream. When something changes, the stream names the affected area and the interface refetches just that data.

GET/api/realtime

A server-sent event stream of change notifications.

Auth: SessionPermission: contacts:read, deals:read or settings:read depending on what you subscribe to

Returns. text/event-stream. An open event on connect, then invalidate events naming the entity that changed.

EntityChanges when
contactsA contact is created, updated, assigned or deleted
dealsA deal is created, updated or deleted
notificationsYou receive a new notification
orgConfigAn administrator changes organization settings
integrationsAn integration is connected, changed or disconnected
Events on the stream
{ "type": "open" }
{ "type": "invalidate", "entity": "contacts" }