Test safely
Credentials beginning with dspk_test_ operate on isolated sandbox data. Use them for development and integration tests.
PUBLIC API · V1
Access workspace data through scoped service-account credentials. The integration API is designed for server-to-server use and keeps sandbox and production data separate.
https://api-go.dashspoke.com/v1Create a service account in your workspace’s Developer settings and grant only the scopes your integration needs. Send its credential as a Bearer token on every request. Credentials are shown only when created or rotated; keep them on your server, never in browser code.
curl --request GET \
--url https://api-go.dashspoke.com/v1/integration/me \
--header 'Authorization: Bearer YOUR_SERVICE_ACCOUNT_KEY' \
--header 'Accept: application/json'
Use GET /integration/me to confirm the active workspace, environment and scopes before synchronizing data.
Credentials beginning with dspk_test_ operate on isolated sandbox data. Use them for development and integration tests.
Credentials beginning with dspk_live_ access the authorized production workspace. Rotate and revoke them in Developer settings.
These are the public service-account endpoints. Dashboard-only and administrative routes are intentionally excluded.
/integration/meAny valid credentialIdentify the service account, workspace, environment and scopes.
/integration/contactscontacts:readList up to 100 contacts. Optional q filters results (maximum 200 characters).
/integration/conversationsconversations:readList up to 100 conversations. Optional status is open, snoozed or resolved; optional q filters results.
/integration/websiteswebsites:readList up to 100 websites in the authorized workspace.
Need machine-readable details? Download the OpenAPI 3.1 specification.
List responses contain data and meta. Authentication failures return 401, missing scopes return 403, invalid filters return 422, and exceeded limits return 429. Errors include a machine-readable code; request IDs can be used when contacting support.
The service-account limit is 600 requests per 60 seconds. Inspect RateLimit-Limit, RateLimit-Remaining and, after a 429, Retry-After. Retry transient failures with bounded exponential backoff.
Configure outbound subscriptions in Developer settings. Verify signatures against the raw request body, enforce the timestamp window, and deduplicate delivery IDs before applying an event. The maintained Go, TypeScript, Python and PHP SDK source under sdk/ includes verification helpers.