Skip to Content
🚀 Sendbox is live — this documentation is a work in progress.
API ReferenceOverview & Authentication

API Reference

Base URL:

https://api.sendboxes.tech/v1

Every path in this reference goes after /v1 (e.g. /v1/campaigns). The same paths without /v1 also work and reach exactly the same endpoints, but new integrations should use /v1.

A machine-readable OpenAPI 3.1 description  lists every endpoint an API key can call, generated from the running server.

Every request/response body is JSON unless noted otherwise (CSV exports return text/csv).

Authentication

Two ways to authenticate, both as a Bearer token:

Create a long-lived API key from Settings → API Keys in the dashboard. It’s shown in full exactly once, at creation — copy it immediately, it cannot be retrieved again.

curl https://api.sendboxes.tech/v1/campaigns \ -H "Authorization: Bearer sb_live_..."

An API key authenticates as the owner of the one workspace it was created in. It’s blocked from account-management actions (billing, team management, workspace settings, branding, and creating/revoking other API keys) — a leaked key can’t touch your billing or invite itself onto your team.

When you create a key you choose:

  • Access: Full access, or Read only. A read-only key can call GET endpoints plus the two that only compute an answer (POST /campaigns/:id/check-spam-words, POST /reply-agents/:id/search); anything that creates, changes, sends or deletes returns 403. Over MCP, a read-only key only sees the read-only tools.
  • Expiry: never, or after 30 days, 90 days or a year. An expired key returns 401 with the date it expired.

Revoke a key any time from the same Settings page. Revoking is immediate and permanent (soft-deleted, never reused).

Never share an API key, commit it to source control, or embed it in client-side code. Treat it like a password to your workspace’s data.

Want an LLM to use this instead of writing code?

See MCP (AI Access) — the same API, exposed as tools your own LLM (Claude, etc.) can call directly, using the same API key.