Setup

Register provider webhooks

POST
/api/v1/setup/provider-webhook

Points the delivery provider's event webhook at this project and stores the signing secret. Without it, messages never advance past sent — deliveries, bounces, opens and complaints all arrive by webhook, and bounce/complaint auto-suppression depends on them. Idempotent; safe on every deploy.

This is inbound plumbing (provider → us). To receive events at your OWN endpoint, see the Webhooks tag.

Authorization

bearerAuth
AuthorizationBearer <token>

An API key from the dashboard under Settings → API keys, sent as Authorization: Bearer aem_….

Authorization has two independent axes.

The scope is ranked — a key satisfies any requirement at or below its own tier:

  • read — see messages, contacts and metrics. Changes nothing, and cannot send.
  • write — everything read does, plus managing templates, contacts, automations, segments and suppressions. This is what editing a template needs.
  • admin — everything write does, plus sending configuration: domains, senders, webhook registration, kill switch, daily cap, brand.

There is no approve scope. It was a rung once; it is not one now, and a key requested with it is rejected.

The approval grant (can_approve) is a separate boolean, not a rung. Delivering mail to a real inbox needs write and the grant. Keeping them on separate axes is what makes the review gate a control rather than a convention: a key that may propose is not automatically a key that may approve its own proposal.

Give your application the lowest tier that works. Most need write and the grant — the dashboard mints that combination as Send + manage; Manage only is the same rung with the grant withheld.

In: header

Response Body

application/json

application/json

application/json

application/json

curl -X POST "https://example.com/api/v1/setup/provider-webhook"
{  "endpoint": "string",  "webhook_id": "string"}