Skip to main content

Base URL

All API requests use the following base URL:
All traffic is routed through a Cloudflare Worker that handles CORS and proxies to the appropriate Supabase Edge Functions.

Authentication

Server-to-server endpoints authenticate via Bearer token using your app secret:
User-facing pages (/start, /manage) use signed JWT links generated with signLink(). See Authentication for details.

Endpoints

The connections and conversations listing share the same path (/api/conversations) but are differentiated by the query parameter: userRef returns connections, connectionId returns conversations.

Response format

All API responses return JSON with Content-Type: application/json. Success responses include endpoint-specific data. Write endpoints include an ok: true field. Error responses return a single error string:

Rate limiting

API endpoints are rate-limited to 60 requests per minute per app. The rate limiter is database-backed (atomic counter per app per minute bucket). Rate limit information is included in response headers:

HTTP status codes