API Reference
Base URL:
https://api.sendboxes.tech/v1Every path in this reference goes after /v1 (e.g. /v1/campaigns). The same paths without
/v1 also work and reach exactly the same endpoints, but new integrations should use /v1.
A machine-readable OpenAPI 3.1 description lists every endpoint an API key can call, generated from the running server.
Every request/response body is JSON unless noted otherwise (CSV exports return text/csv).
Authentication
Two ways to authenticate, both as a Bearer token:
API key (recommended for integrations)
Create a long-lived API key from Settings → API Keys in the dashboard. It’s shown in full exactly once, at creation — copy it immediately, it cannot be retrieved again.
curl https://api.sendboxes.tech/v1/campaigns \
-H "Authorization: Bearer sb_live_..."An API key authenticates as the owner of the one workspace it was created in. It’s blocked from account-management actions (billing, team management, workspace settings, branding, and creating/revoking other API keys) — a leaked key can’t touch your billing or invite itself onto your team.
When you create a key you choose:
- Access: Full access, or Read only. A read-only key can call
GETendpoints plus the two that only compute an answer (POST /campaigns/:id/check-spam-words,POST /reply-agents/:id/search); anything that creates, changes, sends or deletes returns403. Over MCP, a read-only key only sees the read-only tools. - Expiry: never, or after 30 days, 90 days or a year. An expired key returns
401with the date it expired.
Revoke a key any time from the same Settings page. Revoking is immediate and permanent (soft-deleted, never reused).
Never share an API key, commit it to source control, or embed it in client-side code. Treat it like a password to your workspace’s data.
Want an LLM to use this instead of writing code?
See MCP (AI Access) — the same API, exposed as tools your own LLM (Claude, etc.) can call directly, using the same API key.