Skip to main content

Start here

The AzChat API is REST, takes and returns JSON, and uses a simple authentication header. If you already have an account, you can make your first call in two minutes.

API address​

Every example points at the default instance:

https://app.azchat.digital

If you run your own instance (self-hosted or dedicated), swap the host for your own address. Every endpoint in the Reference has a server selector where you enter the host — the code samples and the console then use whatever value you pick.

Generating an API key​

  1. In AzChat, go to Settings → API.
  2. Click Create new key and give it a name that says what it is for (e.g. ERP integration).
  3. Copy the key right away. For security, it is never shown again.

:::warning Scopes are not enforced yet The creation screen lets you tick scopes, but the server does not check them: today any key has full access to the account. Treat every key as a full-access key — do not hand out a "read-only" key believing it is limited. :::

Authenticating​

Send the key in the api_access_token header on every request:

curl --request GET \
--url 'https://app.azchat.digital/api/v1/accounts/1/contacts' \
--header 'api_access_token: SUA_CHAVE_AQUI' \
--header 'accept: application/json'

The 1 in the path is the account ID. You will find it in Settings → API, at the top of the page.

There are three kinds of credential. Most of the API uses the first one:

CredentialWhat for
userApiKeyUser key. Covers almost the whole API, honouring the permissions of the user who owns it.
agentBotApiKeyAgent bot token. Restricted to the bot endpoints.
platformAppApiKeyPlatform app token. Provisions accounts, users and bots.

Details in Authentication.

Testing inside the docs​

Every endpoint in the Reference has a Send API Request button: you fill in the host, paste the key and fire a real request without writing any code. The response shows up right there, and the cURL, Node, Ruby, PHP or Python sample is generated with the values you used.

:::info The console needs CORS enabled The request goes straight from your browser to your instance, so the instance has to accept cross-origin calls. Set the environment variable ENABLE_API_CORS=true on the instance and restart. Without it the browser blocks the call and the console shows a network error — the API itself keeps working normally outside the browser. :::

:::danger There is no sandbox Unlike some other APIs, AzChat has no separate test environment. Whatever you fire from the console really happens, against your production data — including DELETE. To experiment safely, use a test account. :::

How mature this reference is​

These docs cover every endpoint of the API, because they are generated from the application's real routes. But not all of them have been reviewed yet: many carry only the path, the parameters and the body fields derived automatically from the code, with no description and no response example.

Wherever you see the notice about fields "derived automatically from the source code", treat the types as a hint rather than a contract — they are inferred from the field name. Hand-reviewed endpoints do not carry that notice.

Next steps​