How far through setup is this company?
The ten steps of getting a company live, with the same addresses (1.1–3.5) and titles the operator sees in the dashboard. Every done is derived from real rows — there is no stored checklist — so work done through this API, over MCP or by hand all move the same list.
Distinct from GET /api/v1/connection, which answers the narrower deploy-time question 'can this project send right now'. This one also covers the discovery answers, the approved programme and whether the company has sent.
Authorization
bearerAuth An API key from the dashboard under Settings → API keys, sent as Authorization: Bearer aem_….
Authorization has two independent axes.
The scope is ranked — a key satisfies any requirement at or below its own tier:
read— see messages, contacts and metrics. Changes nothing, and cannot send.write— everythingreaddoes, plus managing templates, contacts, automations, segments and suppressions. This is what editing a template needs.admin— everythingwritedoes, plus sending configuration: domains, senders, webhook registration, kill switch, daily cap, brand.
There is no approve scope. It was a rung once; it is not one now, and a key requested with it is rejected.
The approval grant (can_approve) is a separate boolean, not a rung. Delivering mail to a real inbox needs write and the grant. Keeping them on separate axes is what makes the review gate a control rather than a convention: a key that may propose is not automatically a key that may approve its own proposal.
Give your application the lowest tier that works. Most need write and the grant — the dashboard mints that combination as Send + manage; Manage only is the same rung with the grant withheld.
In: header
Response Body
application/json
application/json
application/json
application/json
curl -X GET "https://example.com/api/v1/setup/onboarding"{ "phase": "string", "complete": true, "done_count": 0, "total_count": 0, "next": "string", "steps": [ {} ]}