Shipped surface
Scoped access (company + KB)
Default API keys include lead/inbound scopes only. Super Admin must grantcompanies:* and knowledge:* when approving your key.
Missing scope → 403 with reasonCode: "forbidden" and a missing array.
Company and KB responses never include SMTP passwords, WhatsApp tokens, or file download URLs.
Explicitly not in public API
Custom CRM pattern
- UI: empty API campaign → start
- API:
POST /leads(orPOST /eventswith a mappedeventType) - WhatsApp/email:
GET /omni/templatesthen pass ids +templateVariables/whatsappParams— guide - Optional: Settings webhooks for status callbacks
- Inbound: wire Sheets/Zoho/Custom API in UI →
POST .../crm/lookupwhen you need a read without a live call. Healthcare HMS platforms: Healthcare HMS integration.
Versioning
/api/v1 remains supported ≥ 12 months after any future /api/v2 GA; breaking changes get ≥ 90 days notice.
