Norbelys API
One /v1 of resources. Errors are RFC 9457 problems; lists are cursor pages; effectful requests take an Idempotency-Key.
Version v1
Base URL
https://api.norbelys.comReports
Campaigns
- GETList the workspace's campaigns, newest first by default; the variants' bodies are left out.
/v1/campaigns - POSTCreate a campaign as a `draft`, with its steps, pool, schedule, tracking and stop rules.
/v1/campaigns - GETRetrieve a campaign with its steps and their variants' bodies.
/v1/campaigns/{id} - DELETEDelete a campaign: one that never sent is removed with its steps and enrollments; one that sent is archived, kept for its history, and its live enrollments are stopped.
/v1/campaigns/{id} - PATCHChange a campaign: its settings, its pool, or its steps (the whole ordered list; a changed step gets a new revision for messages not yet created).
/v1/campaigns/{id} - POSTPause a campaign: no new message is created; queued messages wait until it is started again.
/v1/campaigns/{id}/pause - POSTStart a campaign from `draft` or `paused`: it is `materialising` until its job makes it `active` and creates the messages already due.
/v1/campaigns/{id}/start - GETList the workspace's enrollments, newest first by default.
/v1/enrollments - POSTEnroll people into a campaign: up to 100 at once (`201`), more through a job (`202`). Unknown people, suppressed addresses and people already enrolled are skipped.
/v1/enrollments - GETRetrieve an enrollment: its person, position, next run, status and the sender its conversation keeps or waits for.
/v1/enrollments/{id} - POSTStop an enrollment: no further step runs, and its message still queued is cancelled.
/v1/enrollments/{id}/stop
Sending
- GETList the workspace's connections, newest first by default.
/v1/connections - POSTCreate a connection. A credential-based one (SMTP, a relay, the managed MTA) is created in `verifying`, or the workspace's archived connection of the same account comes back with its id, history and identities; a check (or the managed MTA's provisioning) proves it. A Google or Microsoft mailbox answers `202` with the consent URL; the callback creates it.
/v1/connections - GETRetrieve a connection.
/v1/connections/{id} - DELETEArchive a connection: it stops sending, its credential is erased and its folders are no longer read, while its history stays readable and its provider webhook keeps receiving late evidence. Connecting the same account again restores it.
/v1/connections/{id} - PATCHUpdate a connection: pause or resume it, change its pacing, identities or folders, or give it a new credential (then it is verified again).
/v1/connections/{id} - POSTVerify a connection now: it becomes `verifying` and its check runs (the managed MTA's provisioning, for a `norbelys` connection). For an OAuth connection whose grant is lost, the answer carries `authorization.url` for the browser instead, and the ceremony cookie.
/v1/connections/{id}/verify - GETList the workspace's quota scopes, newest first by default.
/v1/quota_scopes - POSTCreate a quota scope.
/v1/quota_scopes - GETRetrieve a quota scope.
/v1/quota_scopes/{id} - DELETEDelete a quota scope and its ledger; its connections keep running without one. Refused while SES connections, archived ones included, name it.
/v1/quota_scopes/{id} - PATCHUpdate a quota scope's limits: each limit given replaces the stored one, `null` clears it.
/v1/quota_scopes/{id} - GETList the workspace's sending domains, newest first by default.
/v1/sending_domains - POSTCreate a sending domain, `pending_verification`, with the DNS records to publish.
/v1/sending_domains - GETRetrieve a sending domain.
/v1/sending_domains/{id} - DELETEDelete a sending domain.
/v1/sending_domains/{id} - PATCHUpdate a sending domain: turn tracking on or off.
/v1/sending_domains/{id} - POSTVerify a sending domain now: it becomes `verifying` and its DNS records are checked.
/v1/sending_domains/{id}/verify
Messages
- GETList the workspace's delivery events, newest first by default.
/v1/delivery_events - GETRetrieve a delivery event.
/v1/delivery_events/{id} - GETList the workspace's messages, newest first by default.
/v1/messages - POSTSend a message: it is queued now and sent when due, outside any campaign's cadence.
/v1/messages - GETRetrieve a message, with its latest attempts, its first delivery events and its holds.
/v1/messages/{id} - POSTCancel a queued message.
/v1/messages/{id}/cancel - POSTRelease a message's holds.
/v1/messages/{id}/release_holds - POSTResolve an uncertain message.
/v1/messages/{id}/resolve
Automation
- GETList the workspace's events, newest first by default. With `after`, only later events, in ascending order unless `order` says otherwise; with `wait`, an empty page waits up to that many seconds (at most 25) for an event to arrive.
/v1/events - POSTCreate a synthetic event with sample data of its type. It is delivered like any other event, to every subscribed endpoint, or only to `webhook_endpoint_id` when given.
/v1/events - GETRetrieve an event.
/v1/events/{id} - GETRetrieve a job of the credential's workspace.
/v1/jobs/{id} - POSTRequest the cancellation of a job: a waiting job is cancelled at once, a running one at its next chunk boundary.
/v1/jobs/{id}/cancel - GETList the workspace's webhook deliveries, newest events first by default (the order is by event, then by delivery).
/v1/webhook_deliveries - GETRetrieve a webhook delivery with its latest attempt.
/v1/webhook_deliveries/{id} - POSTRetry a webhook delivery now. A pending delivery's next attempt is brought forward; a finished one becomes pending again. There is never a second run beside the automatic one.
/v1/webhook_deliveries/{id}/retry - GETList the workspace's webhook endpoints, newest first by default.
/v1/webhook_endpoints - POSTCreate a webhook endpoint. Its signing secret (`whsec_…`) is in this response only.
/v1/webhook_endpoints - GETRetrieve a webhook endpoint (without its secret).
/v1/webhook_endpoints/{id} - DELETEDelete a webhook endpoint and its deliveries.
/v1/webhook_endpoints/{id} - PATCHUpdate a webhook endpoint: its URL, its event types, or whether it is enabled.
/v1/webhook_endpoints/{id} - POSTReplay an endpoint: every delivery of its events created at or after `since` becomes pending with its next attempt now. A disabled endpoint must be enabled first.
/v1/webhook_endpoints/{id}/replay - POSTRotate an endpoint's signing secret. The new secret is in this response only; the old one keeps signing for 24 hours, so every attempt carries both signatures meanwhile.
/v1/webhook_endpoints/{id}/rotate_secret
Audience
- GETList the workspace's exports, newest first by default.
/v1/exports - POSTExport a resource's list to a file. The export runs as a job: poll the export for its link, or listen for `export.completed`. History (`messages`, `attempts`, `delivery_events`, `inbound_messages`) includes the periods already archived out of the database.
/v1/exports - GETRetrieve an export, with a fresh download link when it is ready.
/v1/exports/{id} - GETList the workspace's custom fields (at most 100).
/v1/fields - POSTCreate a custom field.
/v1/fields - DELETEDelete a custom field and every person's value of it. A field a segment uses cannot be deleted.
/v1/fields/{id} - PATCHUpdate a custom field's label or an enum's options. Its key and type never change.
/v1/fields/{id} - GETList the workspace's groups, newest first by default, each with its people counted.
/v1/groups - POSTCreate an empty group.
/v1/groups - GETRetrieve a group with its people counted.
/v1/groups/{id} - DELETEDelete a group and its memberships; its people stay.
/v1/groups/{id} - PATCHRename a group or change its description.
/v1/groups/{id} - GETList the workspace's imports, newest first by default.
/v1/imports - POSTImport people from a CSV file (the body, `Content-Type: text/csv`, at most 16 MiB, its first record the header; `group_id` as a query parameter) or from JSON (`people`, up to 1,000). The import runs as a job: poll the import, or listen for `import.completed`.
/v1/imports - GETRetrieve an import: its status, counts, first problems and the link to its error report.
/v1/imports/{id} - GETList the workspace's people, newest first by default. With `segment_id`, the people the segment's filter matches now.
/v1/people - POSTCreate a person.
/v1/people - GETRetrieve a person.
/v1/people/{id} - DELETEDelete a person and its memberships. A person with enrollments or messages cannot be deleted: its history refers to it.
/v1/people/{id} - PATCHUpdate a person: its address, names, company, custom values (merged) or groups (replaced).
/v1/people/{id} - POSTCheck addresses before mailing them: syntax, DNS routing (MX, an implicit MX, or a null MX that refuses all mail), and the workspace's suppressions and holds. Never a mailbox probe: nothing is sent to the addresses, and nothing is stored. A route the workspace's sending found in DNS within the last day is answered from that, as the sender reads it; any other is asked of DNS now, and a lookup DNS could not answer is `unknown`. In a test-mode workspace only the syntax is checked, as its sender does: its mail never leaves the fake transport.
/v1/preflight - GETList the workspace's segments, newest first by default. A list leaves the counts out.
/v1/segments - POSTCreate a segment; the response counts its people.
/v1/segments - GETRetrieve a segment with its people counted now (up to 10,000).
/v1/segments/{id} - DELETEDelete a segment; its people stay.
/v1/segments/{id} - PATCHRename a segment or replace its filter.
/v1/segments/{id} - GETList the workspace's suppressions, newest first by default.
/v1/suppressions - POSTSuppress an address: no mail of the workspace reaches it any more.
/v1/suppressions - GETRetrieve a suppression.
/v1/suppressions/{id} - DELETERemove a manual suppression; the removal is audited. Suppressions that evidence created are read-only.
/v1/suppressions/{id}
Content
- POSTUpload an image to show in mail. The file is the body, sent with its own `Content-Type` (`image/png`, `image/jpeg`, `image/gif` or `image/webp`), at most 16 MiB; its first bytes must be that format. The answer carries the image's public URL, to use in a message's or a variant's HTML.
/v1/images - DELETEDelete an image. Its public URL stops answering; mail already sent shows it no more, except where a cache kept a copy.
/v1/images/{id}
Inbox
- GETList the messages the inbox read, newest first by default.
/v1/inbound_messages - GETRetrieve a message the inbox read.
/v1/inbound_messages/{id} - PATCHCorrect a message's classification or sentiment by hand; AI never overrides it afterwards.
/v1/inbound_messages/{id} - POSTConfirm or dismiss what an inbound message proposed: confirming applies it (a suppression, or moving the person to the new address a notice gave).
/v1/inbound_messages/{id}/review - GETList the workspace's threads, newest first by default.
/v1/threads - GETRetrieve a thread with its latest 50 messages, outbound and inbound, oldest first.
/v1/threads/{id} - PATCHChange a thread's status (open, snooze or archive it) or mark it read.
/v1/threads/{id}