# API documentation

> HTML version: https://zapped.to/api-documentation

Connect ZAPPED cards, analytics, teams, domains, pixels, and billing data to your own workflows.

Customer keys are managed on one [API keys](https://zapped.to/account-api) page. The account API uses `/api`, managed-profile REST uses `/api/managed-profiles`, and MCP uses `/mcp`. Each surface still requires its own plan access and enabled site controls. Professional includes these API and AI assistant connections. Starter includes dashboard CSV profile import. Custom plans retain their agreed access. Profile publication requires owner review; permitted account API changes to other resources can take effect directly. Webhook signing secrets are separate from API keys.

**Base URL**

`https://zapped.to/api`

## Authentication

Send an API key as a bearer token with each request. Create keys on the [API keys](https://zapped.to/account-api) page of your account. Each key has only the permissions you choose, and each endpoint lists the scope it needs, for example `projects:read` to read projects or `projects:write` to change them. The same key works with the Managed profiles and MCP API when it has those permissions.

```text
Authorization: Bearer YOUR_API_KEY
```

### Example request

```bash
curl --request GET \
  --url 'https://zapped.to/api/{endpoint}' \
  --header 'Authorization: Bearer YOUR_API_KEY'
```

## Errors

API errors return a status code and readable message so your integration can react predictably.

### Error response example

```json
{
    "errors": [
        {
            "title": "api.error_message.no_access",
            "status": 401
        }
    ]
}
```

### Status codes

- **200**: The request was successful.
- **400**: The request was invalid or missing required data.
- **401**: The API key is missing, invalid, expired or revoked.
- **403**: The key lacks a required scope, the plan does not include the feature, or access to the resource is refused. Check the error code.
- **404**: The requested resource was not found.
- **429**: Too many requests were sent too quickly. Each key can make up to 60 requests a minute. Burst, account-wide and concurrent-request limits also apply. Responses include RateLimit-Limit, RateLimit-Remaining and RateLimit-Reset when the minute quota was checked. A 429 response carries Retry-After in seconds.
- **500**: The server could not complete the request.

Dates and times use the UTC timezone unless an endpoint says otherwise.

## Endpoints

Jump into the API resources available for cards, analytics, teams, billing, and account activity.

- [Managed profiles and MCP](https://zapped.to/api-documentation/managed-profiles.md): Prepare private profile drafts and bulk imports, request the owner's review and publish only the versions the owner approved, over REST or MCP.
- [Lead webhooks](https://zapped.to/api-documentation/lead-webhooks.md): Receive each new lead as a signed JSON POST: headers, payload fields, signature verification, retries and test events.
- [User account](https://zapped.to/api-documentation/user.md): Read the account that owns the API key.
- [Cards](https://zapped.to/api-documentation/vcards.md): List the account's digital business cards and read one card.
- [Statistics](https://zapped.to/api-documentation/statistics.md): Read a card's visits and interactions over a date range, grouped by one dimension.
- [Projects](https://zapped.to/api-documentation/projects.md): List, read, create, update and delete the projects that group cards.
- [Pixels](https://zapped.to/api-documentation/pixels.md): List, read, create, update and delete tracking pixels.
- [Domains](https://zapped.to/api-documentation/domains.md): List available domains and manage the account's custom domains.
- [Teams](https://zapped.to/api-documentation/teams.md): List, read, create, update and delete the teams the account owns.
- [Team members](https://zapped.to/api-documentation/team-members.md): Invite, read, update and remove members of a team the account owns.
- [Team access](https://zapped.to/api-documentation/teams-member.md): List and read the teams the account is a member of, and update or leave them.
- [Payments](https://zapped.to/api-documentation/payments.md): List and read the account's payments.
- [Account logs](https://zapped.to/api-documentation/users-logs.md): Read the account activity log.
- [Managed profiles OpenAPI 3.1 contract](https://zapped.to/api-documentation/managed-profiles-openapi): Machine-readable contract for the managed profiles API.
