Public liveness
OpenAPI 3.1.0 · contract 2.2.0
API reference
Generated from the same contract as the server and official SDK operation manifest. It currently contains 256 method-and-path operations.
Health
Openapi.Json
OpenAPI 3.1 document
Me
Authenticated caller and bindings
Messages
Accept a notification
Canonical send alias
Validate and durably accept an idempotent batch of up to 100 messages
Validate without dispatch
Persist a deterministic no-provider policy and payload preview
Persist a deterministic no-provider audience and cost estimate
Tenant-scoped message state
Canceled before provider dispatch
Every still-unsent delivery paused and prior broker generations invalidated
Paused deliveries re-armed with the current dispatch generation
Selected failed deliveries re-armed through accounted replay jobs
Delivery decisions and state trace
Exportable tenant-scoped diagnostic bundle without provider secrets
Projects
Projects
Created
Apps
Applications
Created
Application
Updated
Public VAPID key
Rotated and activated
Encrypted, validated, and activated
Encrypted, validated, and activated
Application statistics
Delivery analytics with honest state separation
Installations
Latest secret-free SDK health evidence and stale/missing counts for active installations
Immutable SDK configuration versions and active publication pointer
Immutable secret-free SDK configuration version created
SDK configuration publication pointer moved atomically
Provider and device delivery states
Key returned once
Topics
Topic saved
Member added
Member removed
Effective explicit preferences
Preference saved and audited
Consent ledger
Append-only consent evidence recorded
Stable tenant sequence cursor, ordering key, schema version, and canonical payload
Immutable versioned schemas and PII classifications
Inbox feeds
Versioned feed configuration saved
Cursor-paginated user inbox with cross-device versioned state
Retention, minimum aggregation, user-level analytics, IP masking, and deletion-propagation policy
Privacy policy saved and audited
Versioned draft, published, and retired attribution models
Saved and scheduled report definitions
Latest 200 immutable report run records
Latest immutable digest-rule versions
Explainable 30-day attention ledger and deterministic fatigue score
Locale, timezone, channel, device, and business-hours delivery preferences
Validated delivery profile saved
Effective tenant and application attention policies
Frequency and fatigue policy saved
Versioned brand kits
Draft brand kit created
Integrity-addressed media registry
HTTPS media metadata registered
Localized content bundles
Draft content bundle created
Redacted replaceable channel connectors
Validated connector stored with encrypted credentials
Normalized user channel destination saved
Migration sources with encrypted configuration redacted
Encrypted migration source created
Recent persisted shadow comparison evidence
Deterministic migration allocation, rollback generation, and latest readiness evidence
Dual-run allocation saved without changing existing cohort assignments
New routes atomically switched to the source provider; existing delivery ownership is unchanged
Persisted cohort sample, duplicate, stale-route, and success-rate readiness gates
Recent delivery-owner assignments and cross-provider evidence
Redacted active credential and candidate approval metadata
Installations
Idempotently registered installation and receipt token
Identity, permission, capability, or version updated
Installation and subscriptions revoked
Compatible protocol and checksum-aware remote configuration, or an explicit fail-closed upgrade status
Provider token or Web Push subscription rotated with append-only hashed evidence
Append-only secret-free SDK health evidence accepted
Installation-authorized explicit consent preferences, including anonymous state
Replay-safe explicit preference and append-only consent evidence stored
Subscriptions
Token rotated
Users
User upserted
Receipts
Authenticated monotonic device or engagement receipt
Stream
Server-sent event stream
Webhooks
Webhooks
SSRF-validated webhook and signing secret
Deleted
Test queued
Templates
Templates
Immutable template version published
Events
Idempotently ingest a customer event
Ingest up to 100 events atomically
Event Destinations
Bound destinations with encrypted configuration redacted and honest activation state
Executable signed HTTPS destination created; generated secret is shown once
Destination paused with an audited reason
Validated signed HTTPS destination resumed
Signing secret envelope rotated and new secret shown once
Delivery, retry, dead-letter, response, cursor, and payload-checksum evidence
Confirmed bounded replay queued
Event Replays
Caller-app-bound replay and backfill jobs
Event Schemas
New immutable active schema version; prior version retired
Inbox
Authenticated cursor-paginated device inbox, feed counts, unread count, and masked sensitive content
Inbox notification durably queued
Marked read with authoritative state version
Marked unread with authoritative state version
Archived with authoritative state version
Restored with authoritative state version
Snoozed until a validated future time
Pinned
Unpinned
Saved
Unsaved
Soft-deleted for this user
Replay-safe mark-all result and remaining unread count
Declared action accepted or identically replayed
Thread muted with authoritative state version
Thread unmuted with authoritative state version
Object followed with authoritative state version
Object unfollowed with authoritative state version
Short-lived installation-bound redirect to the validated active asset
Workflows
Workflows
Workflow shell saved
Workflow and immutable version history
Mutable workflow name or pause state updated
Workflow archived
Immutable validated version created
Exact immutable workflow-as-code specification and qualification state
Published
Approval requested
Approved by a distinct authenticated subject
Durable idempotent run queued
Latest revisioned visual journey canvas
New optimistic-concurrency canvas revision saved
Exact graph, layout, and workflow validation result
Valid canvas compiled idempotently to an immutable workflow version
Bounded deterministic trace with no external side effects
Workflow Runs
Run and step trace
Canceled
Distinct authenticated approver resumed run
Segments
Versioned audience segments
Segment created
Membership activated
Membership exited
Campaigns
Campaigns
Campaign shell created
Campaign and immutable versions
Validated immutable campaign version
Canonical render and policy warnings
Live recipient and dispatch estimate; cost is never fabricated
Approval requested
Approved by a distinct subject
Qualified campaign published
Idempotent durable run queued
Campaign Runs
Snapshot and dispatch counters
Unsent fan-out paused
Durable fan-out resumed
Unsent fan-out canceled; provider-accepted messages cannot be recalled
Experiments
Experiments and assignment counts
Weighted deterministic experiment created
Experiment started after weight, control, metric, and collision validation
Experiment assignment paused; existing evidence remains immutable
Experiment resumed after mutual-exclusion check
Experiment manually completed without automatic winner rollout
Stable user- or organization-level assignment; this does not record exposure
Privacy-safe exposure durably recorded
Declared metric observation recorded after a proven exposure
Append-only frequentist and Bayesian sequential analysis created
Latest append-only result with samples, lift, confidence intervals, p-values, Bayesian probability and guardrails
Evidence-backed winner sent for four-eyes approval
Different actor approved the recommended winner; no rollout is performed automatically
Conversions
Idempotent conversion and revenue attribution accepted
Attribution Models
Exact idempotent replay
Published by an actor different from the author; prior published version retired
Reports
Exact definition replay
Exact idempotent report replay
Exact idempotent replay
Report Runs
Report columns, bounded rows, summary, and checksum
Exports
Exact idempotent replay
Export lifecycle, size, expiry, and SHA-256 metadata
CSV or JSON Lines artifact
Digest Rules
Identical definition replay
User-controlled digest schedule saved
Deterministic non-delivering digest preview with overflow evidence
Digest Items
Idempotent digest item enqueued
Digest Batches
Durable materialization, render, and dispatch lifecycle
Routing
Explainably choose channel, device, provider, and delivery time
In App Experiences
Tenant-scoped in-app authoring versions and qualification state
Immutable validated in-app experience version created for one of the 22 canonical formats
Canonical format, eligibility, frequency, and content preview; records the publish gate
Previewed experience version published by a distinct actor
Authenticated device feed with specification and policy, filtered by device, user, bounded runtime context, session/mutual exclusion, terminal state, frequency caps, and cooldown
Checksum-bound idempotent eligibility, impression, dismissal, action, completion, or conversion event
Live Notifications
Cross-platform live object and fallback dispatch started
Monotonic rate-protected live update
Terminal live state and final fallback dispatched
Brand Kits
Immutable validated brand version created
Brand version published by a distinct actor
Content Bundles
Immutable content version with strict variables created
Locale overlay saved as draft
Localization approved by a distinct actor
Content version published after translation approval
Strict variable-safe localized render, fallback trace, direction, and warnings
Channel Connectors
Connector disabled and encrypted configuration erased
Confirmed audited circuit reset for a tenant connector
Channel Messages
Durably accept an email, SMS, WhatsApp, RCS, collaboration, or custom-channel message
Tenant-scoped channel state; provider acceptance is not confirmed delivery
Idempotent monotonic provider receipt recorded
Migration Sources
Idempotent replay
Migration Jobs
Records normalized, secret fields redacted from staging, and optionally applied transactionally
Readiness score, gates, counts, and remediation recommendations
Import counts and redacted record evidence
Shadow
Persisted no-delivery audience, suppression, channel, and render comparison; unknown cost and latency remain null
Dual Run
Assign exactly one delivery owner using a stable deterministic cohort
Dual Run Routes
Idempotent monotonic source-provider outcome recorded
Roles
Built-in and tenant custom roles with effective permissions
Custom role created by tenant owner
Custom role replaced and assigned sessions revoked
Custom role and assignments removed; assigned sessions revoked
Role Assignments
Custom role assigned and existing subject sessions revoked
Assignment removed and existing subject sessions revoked
Member App Access
Application and environment access replaced; existing sessions revoked
Security Policy
IP, mTLS, authentication, credential-approval and session policy
Owner-updated policy; prior sessions revoked
Sessions
Current subject sessions or administrator-selected subject sessions
Session revoked immediately
Security Alerts
New-session-device and future tenant security evidence
Alert acknowledged with actor and time evidence
Support Access
Complete customer-controlled support access trail
Bounded support access request awaiting a distinct owner
Distinct owner approved time-limited scopes
Support access revoked immediately
Provider Credential Changes
Distinct actor atomically activates a validated encrypted candidate
Audit Events
Filtered append-only hash-chained tenant audit events
Full-row hash and predecessor-link verification for the tenant audit chain
Bounded immutable audit snapshot ready for download
Audit Exports
Tenant-scoped NDJSON or JSON audit evidence
Customer Key Configuration
Customer key provider metadata and honest validation status
KMS/HSM metadata recorded pending external validation; not falsely activated
Status
Customer-visible current and recent public incident history
Dead Letters
Tenant-scoped redacted dead-letter ledger
Confirmed idempotent replay started from authoritative outbox state
Replay Jobs
Manual replay request and terminal outcome evidence
Provider Health
Current circuit state and latest provider health snapshots
Provider Circuits
Confirmed audited circuit reset for a bound application
Incidents
Tenant-specific and public incident history with updates
Usage
Live idempotent meter totals, budgets, and null cost when no approved rate exists
Usage Budgets
Application or tenant meter budget and hard limit stored
Usage Budget Alerts
Budget threshold alert acknowledged with actor evidence
Slo Report
Approved SLO definitions, latest measurements, and live backlog evidence
Demo
Interactive first-party device test page
Demo Sw.Js
Service worker for the device test page