Create a free digital business card, then share it by link, QR code, or NFC tap.
Developers

API documentation

Connect ZAPPED cards, analytics, teams, domains, pixels, and billing data to your own workflows.

Base URL https://zapped.to/api Use bearer authentication for every request.

Customer keys are managed on one API keys page. The account API uses /api, managed-profile REST uses /api/managed-profiles, and MCP uses /mcp. Each surface still requires its own plan access and enabled site controls. Professional includes these API and AI assistant connections. Starter includes dashboard CSV profile import. Custom plans retain their agreed access. Profile publication requires owner review; permitted account API changes to other resources can take effect directly. Webhook signing secrets are separate from API keys.

Authentication

Send an API key as a bearer token with each request. Create keys on the API keys page of your account. Each key has only the permissions you choose, and each endpoint lists the scope it needs, for example projects:read to read projects or projects:write to change them. The same key works with the Managed profiles and MCP API when it has those permissions.

Authorization: Bearer YOUR_API_KEY

Example request

curl --request GET \
--url 'https://zapped.to/api/{endpoint}' \
--header 'Authorization: Bearer YOUR_API_KEY' \

Errors

API errors return a status code and readable message so your integration can react predictably.

Error response example

{
    "errors": [
        {
            "title": "api.error_message.no_access",
            "status": 401
        }
    ]
}

Status codes

200 The request was successful.
400 The request was invalid or missing required data.
401 The API key is missing, invalid, expired or revoked.
403 The key lacks a required scope, the plan does not include the feature, or access to the resource is refused. Check the error code.
404 The requested resource was not found.
429 Too many requests were sent too quickly. Each key can make up to 60 requests a minute. Burst, account-wide and concurrent-request limits also apply. Responses include RateLimit-Limit, RateLimit-Remaining and RateLimit-Reset when the minute quota was checked. A 429 response carries Retry-After in seconds.
500 The server could not complete the request.
Dates and times use the UTC timezone unless an endpoint says otherwise.

Endpoints

Jump into the API resources available for cards, analytics, teams, billing, and account activity.

Managed profiles and MCP Uses an API key
Lead webhooks Receiver reference
User account
Cards
Statistics
Projects
Pixels
Domains
Teams
Team members
Team access
Payments
Account logs