> ## Documentation Index
> Fetch the complete documentation index at: https://docs.norbelys.com/llms.txt
> Use this file to discover all available pages before exploring further.

# List connectable apps

> Every app you can connect, searchable — the featured ones (which carry first-class behaviour like lead import, meeting/deal events and notifications) come first. Pass a `slug` from here to `connect`.



## OpenAPI

````yaml /openapi.json get /integrations/catalog
openapi: 3.1.1
info:
  description: >-
    The **Norbelys API** is a single, predictable REST surface for cold email
    and

    outreach — people, senders, programs, and sending all live behind the five

    patterns below. Developer-first and AI-first: every name is either already

    invented (Schema.org) or obvious.


    ## Authentication


    Every request authenticates with an **org-scoped API key**. Create one in

    **Settings → API keys** and send it as a bearer token:


    ```http

    GET https://api.norbelys.com/v1/people

    Authorization: Bearer ak_live_…

    ```


    Interactive agents may instead use OAuth 2.1 (see `/auth.md` and the

    `/.well-known/oauth-protected-resource` metadata).


    ## Conventions


    - **Base URL** — `https://api.norbelys.com/v1`.

    - **JSON in, JSON out.** Timestamps are ISO-8601 in UTC.

    - **Cursor pagination.** List endpoints take `limit` + `cursor` and return
      `{ data, hasMore, nextCursor }` (offset-paged tables add `page` + `total`).
    - **Expansions.** Detail GETs take an `expand[]` query param to inline
    related
      data (e.g. `GET /people/{id}?expand[]=timeline`) instead of extra calls.
    - **Soft deletes.** Anything that has been used is archived, never
    hard-deleted —
      `DELETE` archives the resource and returns it.

    ## Errors


    Failures return the same envelope on every 4xx/5xx, with the matching HTTP
    status:


    ```json

    { "error": { "type": "invalid_request", "code": "invalid_param",
                "message": "…", "hint": "…", "doc_url": "…" } }
    ```


    `type` is a broad, machine-routable category derived from the status; `code`
    is the

    stable machine contract you branch on (never the human `message`). See the
    `ApiError`

    schema.


    ## Idempotency


    Every `POST` accepts an optional **`Idempotency-Key`** header. Reuse the
    same key to

    replay the original result for 24h instead of re-executing — so a retried
    create can

    never double-charge or duplicate a record.


    ## Rate limits & versioning


    Abuse control is enforced at the edge; responses advertise the policy via
    the

    `RateLimit-Policy` header, and a `429` carries `Retry-After`. The API is
    versioned in

    the URL path (`/v1`). Breaking changes ship under a new version; a retiring
    surface is

    announced with `Deprecation` + `Sunset` response headers at least 90 days
    ahead.
  title: Norbelys API
  version: 0.0.1
  x-api-lifecycle:
    currentVersion: v1
    deprecationPolicyUrl: https://docs.norbelys.com/conventions#versioning
    deprecationSignals:
      - Deprecation header
      - Sunset header
    minNoticeDays: 90
    versioning: url-path
servers:
  - description: Production
    url: https://api.norbelys.com/v1
security:
  - bearerAuth: []
tags:
  - description: Your workspace — profile and onboarding state.
    name: Organization
  - description: >-
      The people you reach out to: create, import, segment, and read a person's
      timeline.
    name: People
  - description: >-
      Custom person fields — the tenant-defined attributes that ride on every
      person under `customFields`.
    name: Fields
  - description: >-
      Static lists of people — hand-curated audiences you add to and remove
      from.
    name: Groups
  - description: >-
      Saved audience filters — dynamic rule-trees evaluated live against your
      people.
    name: Segments
  - description: >-
      Connected mailboxes that send your email — the sending identity behind
      each program.
    name: Senders
  - description: >-
      Every domain concern in one place: sending domains (verification, DNS
      records, daily caps) and DMARC monitoring (collection addresses, ingested
      reports).
    name: Domains
  - description: >-
      Campaigns and sequences — with their steps, variants and enrollments
      nested underneath.
    name: Programs
  - description: >-
      Send email through the unified send door, read the unified sent/received
      log, and fetch a message's exact sent source.
    name: Messages
  - description: >-
      The one analytics door: named catalog queries (funnels, feeds, health,
      A/B, DMARC) over the event store.
    name: Analytics
  - description: Addresses excluded from sending — unsubscribes, bounces, and complaints.
    name: Suppressions
  - description: >-
      Connected tools (Slack, CRMs): mint a Connect session, configure
      notifications, disconnect.
    name: Integrations
  - description: >-
      Synchronous email verification — deliverability, reachability, and
      identity signals for an address.
    name: Verify
  - name: Files
paths:
  /integrations/catalog:
    get:
      tags:
        - Integrations
      summary: List connectable apps
      description: >-
        Every app you can connect, searchable — the featured ones (which carry
        first-class behaviour like lead import, meeting/deal events and
        notifications) come first. Pass a `slug` from here to `connect`.
      operationId: integrations.catalog
      parameters:
        - name: category
          in: query
          schema:
            type: string
            description: Filter to one category slug.
            examples:
              - crm
          allowEmptyValue: true
          allowReserved: true
        - name: limit
          in: query
          schema:
            type: integer
            minimum: 1
            maximum: 100
            description: How many apps to return, 1-100. Defaults to 50.
          allowEmptyValue: true
          allowReserved: true
        - name: search
          in: query
          schema:
            type: string
            description: Free-text search over app names and descriptions.
            examples:
              - spreadsheet
          allowEmptyValue: true
          allowReserved: true
      responses:
        '200':
          description: OK
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/IntegrationCatalog'
        '400':
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/ApiError'
          description: The request was malformed or failed validation.
        '401':
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/ApiError'
          description: Missing or invalid credentials.
        '403':
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/ApiError'
          description: Authenticated, but not permitted.
        '404':
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/ApiError'
          description: No such resource (or it has been archived).
        '409':
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/ApiError'
          description: The request conflicts with the resource's current state.
        '422':
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/ApiError'
          description: Well-formed but semantically invalid.
        '429':
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/ApiError'
          description: Rate limit exceeded — retry after the `Retry-After` interval.
        '500':
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/ApiError'
          description: An unexpected error on our side.
      x-codeSamples:
        - label: TypeScript / JavaScript
          lang: typescript
          source: >-
            import { createClient } from "@norbelys/sdk";


            const norbelys = createClient({ apiKey: process.env.NORBELYS_API_KEY
            });


            const { data, error } = await norbelys.integrations.catalog();

            if (error) {
              throw new Error(error.error.message);
            }

            console.log(data);
        - label: Python
          lang: python
          source: >-
            import norbelys


            config = norbelys.Configuration(host="https://api.norbelys.com/v1",
            access_token="ak_live_…")

            with norbelys.ApiClient(config) as client:
                api = norbelys.IntegrationsApi(client)
                result = api.integrations_catalog()
                print(result)
        - label: Go
          lang: go
          source: >-
            cfg := norbelys.NewConfiguration()

            cfg.Servers = norbelys.ServerConfigurations{{URL:
            "https://api.norbelys.com/v1"}}

            client := norbelys.NewAPIClient(cfg)

            ctx := context.WithValue(context.Background(),
            norbelys.ContextAccessToken, "ak_live_…")


            result, _, err :=
            client.IntegrationsAPI.IntegrationsCatalog(ctx).Execute()
        - label: Ruby
          lang: ruby
          source: |-
            require "norbelys"

            Norbelys.configure { |c| c.access_token = ENV["NORBELYS_API_KEY"] }
            api = Norbelys::IntegrationsApi.new
            result = api.integrations_catalog()
            puts result
        - label: CLI
          lang: bash
          source: norbelys integrations catalog
        - label: curl
          lang: bash
          source: |-
            curl -X GET "https://api.norbelys.com/v1/integrations/catalog" \
              -H "Authorization: Bearer $NORBELYS_API_KEY"
components:
  schemas:
    IntegrationCatalog:
      type: object
      properties:
        apps:
          type: array
          items:
            $ref: '#/components/schemas/IntegrationApp'
          description: The apps you can connect, featured ones first.
      required:
        - apps
      title: IntegrationCatalog
    ApiError:
      properties:
        error:
          properties:
            code:
              description: >-
                Stable machine code — branch on this, never on the human
                `message`.
              enum:
                - invalid_param
                - missing_param
                - invalid_expand
                - duplicate_email
                - already_exists
                - unauthorized
                - forbidden
                - mailbox_already_connected
                - suppression_protected
                - program_not_launchable
                - database_unavailable
                - rate_limited
                - idempotency_key_reuse
                - idempotency_in_progress
              type: string
            doc_url:
              description: Optional link to the relevant documentation.
              format: uri
              type: string
            hint:
              description: Optional one-sentence remediation.
              type: string
            message:
              description: Human-readable explanation. Never a contract.
              type: string
            type:
              description: Broad, machine-routable category derived from the HTTP status.
              examples:
                - invalid_request
                - authentication_error
                - rate_limit
              type: string
          required:
            - type
            - code
            - message
          title: ApiErrorDetail
          type: object
      required:
        - error
      title: ApiError
      type: object
    IntegrationApp:
      type: object
      properties:
        categories:
          type: array
          items:
            type: string
          default: []
          description: Category slugs this app belongs to.
          examples:
            - - crm
              - sales
        description:
          anyOf:
            - type: string
            - type: 'null'
          description: One-line description of the app, or null.
          examples:
            - Inbound marketing, sales, and CRM platform.
        featured:
          type: boolean
          description: >-
            True for the apps Norbelys leads with (they carry first-class
            behaviour: lead import, meeting/deal events, notifications).
        logo:
          anyOf:
            - type: string
            - type: 'null'
          description: Logo URL for the app, or null.
          examples:
            - https://logos.composio.dev/api/hubspot
        name:
          type: string
          description: The app's display name.
          examples:
            - HubSpot
        object:
          const: integration_app
          default: integration_app
          description: Always "integration_app".
        slug:
          $ref: '#/components/schemas/IntegrationProvider'
          description: The app slug — pass it to `POST /v1/integrations/connect`.
      required:
        - description
        - featured
        - logo
        - name
        - slug
      title: IntegrationApp
    IntegrationProvider:
      type: string
      minLength: 1
      title: IntegrationProvider
      description: The connected app for this integration.
      examples:
        - slack
  securitySchemes:
    bearerAuth:
      description: >-
        Org-scoped Norbelys API key. Create one in Settings → API keys and send
        it as `Authorization: Bearer ak_…`.
      scheme: bearer
      type: http

````