Base URL
Authentication
Project and organisation operations require a bearer token. Public form submissions use the form token in the URL; follow that endpoint’s generated contract. See the Authentication guide for key types, scopes, and rotation.Conventions
Main API conventions have different rollout states. Cursor pagination and theX-Request-Id correlation header are available. Check the linked guides before relying on per-key rate limits, idempotency enforcement, strict version validation, or a particular error media type.
Endpoints
Endpoint pages are auto-generated from the OpenAPI specification. See the sidebar for the full list, grouped by resource (Users, CRM, Lists, Subscriptions, Campaigns, Journeys, Templates, Events, Tags, Projects, API keys, Organisation, Webhooks, Billing recovery, Form definitions and Form submissions).
CRM access
CRM endpoints use the project-scoped/client surface. Generated CRM paths such as /crm/contacts are relative to:
sk_) in the Authorization header. CRM reads require a secret project key. CRM writes require a secret project key with the project editor role or higher.
Public CRM properties appear in each record’s properties object. Hidden and classified CRM properties are not exposed in CRM API responses.
OpenAPI spec URL: https://apix.spotzee.com/api/openapi.json
Next steps
CRM guide
Organise contacts, companies, activities, and pipeline stages.
Authentication
Key types, scopes, and rotation.
Errors
Status codes and the
code catalogue.