Integrazioni · API REST e webhook

Ogni pulsante della dashboard, come endpoint

Un'API REST versionata e 145 eventi webhook firmati, dietro token di cui decidi tu i permessi, su ogni piano

Everything the dashboard can do, code can do: 30 resource families on a versioned API described by a published OpenAPI spec, personal access tokens that carry only the abilities you tick, writes that accept an idempotency key so a retry never duplicates, and 145 events posted to your endpoints with an HMAC signature and a retry ladder that keeps trying for about 4 days. The REST endpoint and the MCP tool for an operation share the same action underneath, so an agent, a Zap and your own service all do exactly what the dashboard would.

Superficie
30 famiglie di risorse
Progetti, piani, pass, abbonamenti, membri, coupon, codici di accesso, broadcast, supporto, connettori, ripristino e altro, su un percorso versionato con una specifica OpenAPI pubblicata.
Token
107 permessi limitati
Un token di accesso personale porta solo i permessi che spunti; i token di produzione e di test si distinguono dal prefisso e vengono rifiutati nell'ambiente sbagliato.
Limiti
300 al minuto, 10,000 all'ora, per token
Più limiti più stretti su pochi endpoint pesanti; ogni risposta dice quanto resta e una richiesta limitata dice quando riprovare.
Webhook
145 eventi firmati
HMAC-SHA256 su timestamp e corpo, un registro delle consegne e 8 tentativi in circa 4 giorni quando il tuo endpoint non risponde.
Idempotenza
Ripetizioni servite per 24 ore
Invia una chiave di idempotenza con una scrittura e un nuovo tentativo restituisce la prima risposta invece di un secondo record.
Incluso in
Ogni piano, Free incluso
L'API, i webhook, la specifica OpenAPI e il server MCP non costano nulla in più su nessun piano.

What the API gives you

One spec, any toolkit

The OpenAPI document imports into Postman or Insomnia for exploring, into a code generator for a typed client, and into a LangChain toolkit for an agent, with no hand-written client.

Least privilege, by ability

Tokens carry abilities, not roles: a reporting service holds the reads it needs and nothing else, a checkout service holds one write, and rotating a token stops everything that used it.

Events you can trust

Every webhook is signed, retried on a widening ladder and logged with each attempt; message bodies for support events stay out of the payload, fetched over the API when you need them.

Built with agents in mind

The REST endpoint and the MCP tool for one operation share one action, error codes are a catalogue you can read, and async jobs report their progress, so a machine can drive the platform as safely as a person.

How to start

  1. 1

    Create a personal access token under Settings, API tokens, ticking only the abilities you need; use a test token against a test project first.

  2. 2

    Import the OpenAPI spec into Postman or Insomnia, or generate a typed client from it, and make your first read.

  3. 3

    Add an idempotency key header to every write, so a retry after a timeout returns the first response.

  4. 4

    Add a webhook endpoint, pick the events, store the secret, and verify the signature on every delivery before acting on it.

  5. 5

    Watch the delivery log and the rate-limit headers, and read the versioning page before you build on anything marked as changing.

Leggi la guida

Ideale per

  • Developers building a checkout, a CRM sync or a reporting service
  • Agencies running many communities from one system
  • Anyone who wants the platform to fit their stack rather than the reverse

Domande comuni

Leggi la guida
01

L'API è sul piano Free?

Sì. L'API, i webhook, la specifica OpenAPI e il server MCP sono su ogni piano, Free incluso, con gli stessi limiti.

02

Come vengono limitati i token?

Per permesso, tra 107: spunti ciò che un token può fare quando lo crei, e una richiesta fuori da quella lista viene rifiutata con un errore chiaro. I token di produzione e di test portano prefissi diversi e vengono rifiutati nell'ambiente sbagliato.

03

Quali sono i limiti di frequenza?

300 richieste al minuto e 10,000 all'ora per token, con limiti più stretti su pochi endpoint pesanti come la generazione massiva di codici; gli header di risposta dicono quanto resta e una richiesta limitata dice quando riprovare.

04

Cosa succede quando il mio endpoint webhook non risponde?

Subscriby riprova la consegna fino a 8 volte in circa 4 giorni con una scala crescente, registra ogni tentativo e segna la consegna quando il tuo endpoint risponde con successo. Le consegne non sono rigorosamente ordinate nei tentativi, quindi agisci sui dati dell'evento e non sul suo ordine di arrivo.

05

Come evito i duplicati nei tentativi ripetuti?

Invia una chiave di idempotenza con ogni scrittura. Una ripetizione con la stessa chiave entro 24 ore restituisce la risposta ricevuta dal primo tentativo, quindi una richiesta ripetuta non crea mai un secondo codice, coupon o risposta.

Inizia gratis — Leggi la specifica, fai la prima chiamata

Il piano gratuito include 3 progetti. Nessun costo mensile — è richiesta una carta per addebitare le commissioni di transazione.

Configurazione gratuita in 30 minuti
Le nostre roadmap