Every Button in the Dashboard, as an Endpoint
A versioned REST API and 145 signed webhook events, behind tokens you scope yourself, on every plan
Everything the dashboard can do, code can do: 30 resource families on a versioned API described by a published OpenAPI spec, personal access tokens that carry only the abilities you tick, writes that accept an idempotency key so a retry never duplicates, and 145 events posted to your endpoints with an HMAC signature and a retry ladder that keeps trying for about 4 days. The REST endpoint and the MCP tool for an operation share the same action underneath, so an agent, a Zap and your own service all do exactly what the dashboard would.
- Surface
- 30 resource families
- Projects, plans, passes, subscriptions, members, coupons, access codes, broadcasts, support, connectors, recovery and more, on a versioned path with a published OpenAPI spec.
- Tokens
- 107 scoped abilities
- A personal access token carries only the abilities you tick; live and test tokens are told apart by prefix and refused in the wrong environment.
- Limits
- 300 a minute, 10,000 an hour, per token
- Plus tighter buckets on a few heavy endpoints; every response says how much is left and a limited request says when to retry.
- Webhooks
- 145 signed events
- HMAC-SHA256 over the timestamp and body, a delivery log, and 8 attempts over about 4 days when your endpoint is down.
- Idempotency
- Replays answered for 24 hours
- Send an idempotency key with a write and a retry returns the first response instead of a second record.
- Included on
- Every plan, including Free
- The API, the webhooks, the OpenAPI spec and the MCP server cost nothing extra on any plan.
What the API gives you
One spec, any toolkit
The OpenAPI document imports into Postman or Insomnia for exploring, into a code generator for a typed client, and into a LangChain toolkit for an agent, with no hand-written client.
Least privilege, by ability
Tokens carry abilities, not roles: a reporting service holds the reads it needs and nothing else, a checkout service holds one write, and rotating a token stops everything that used it.
Events you can trust
Every webhook is signed, retried on a widening ladder and logged with each attempt; message bodies for support events stay out of the payload, fetched over the API when you need them.
Built with agents in mind
The REST endpoint and the MCP tool for one operation share one action, error codes are a catalogue you can read, and async jobs report their progress, so a machine can drive the platform as safely as a person.
How to start
- 1
Create a personal access token under Settings, API tokens, ticking only the abilities you need; use a test token against a test project first.
- 2
Import the OpenAPI spec into Postman or Insomnia, or generate a typed client from it, and make your first read.
- 3
Add an idempotency key header to every write, so a retry after a timeout returns the first response.
- 4
Add a webhook endpoint, pick the events, store the secret, and verify the signature on every delivery before acting on it.
- 5
Watch the delivery log and the rate-limit headers, and read the versioning page before you build on anything marked as changing.
Best for
- Developers building a checkout, a CRM sync or a reporting service
- Agencies running many communities from one system
- Anyone who wants the platform to fit their stack rather than the reverse
Often paired with
The integrations creators wire in beside this one.
Common Questions
Read the guideIs the API on the Free plan?
Yes. The API, the webhooks, the OpenAPI spec and the MCP server are on every plan, including Free, with the same limits.
How are tokens scoped?
By ability, out of 107: you tick what a token may do when you create it, and a request outside that list is refused with a clear error. Live and test tokens carry different prefixes and are refused in the wrong environment.
What are the rate limits?
300 requests a minute and 10,000 an hour per token, with tighter buckets on a few heavy endpoints such as bulk code generation; the response headers say how much remains and a limited request says when to retry.
What happens when my webhook endpoint is down?
Subscriby retries the delivery up to 8 times over about 4 days on a widening ladder, logs every attempt, and marks the delivery once your endpoint answers with a success. Deliveries are not strictly ordered under retry, so act on the event's data rather than its arrival order.
How do I avoid duplicates on retry?
Send an idempotency key with every write. A replay with the same key within 24 hours returns the response the first attempt received, so a retried request never creates a second code, coupon or reply.
Start Free — Read the Spec, Make the First Call
Free plan includes 3 projects. No monthly fee — card on file required to charge transaction fees.
Set Up Free in 30 Minutes