Developers
Public API & webhooks
Authenticate server-to-server calls with a scoped service-account token, and receive signed webhook deliveries for CRM/lead events.
Service account tokens
Create a scoped, expiring bearer token for server-to-server access instead of sharing a user's session.
- Scopes: read, write, webhooks
- Optional expiry in days
- Rotate or revoke without downtime for other tokens
Authenticating public API requests
Send the token as a standard bearer credential; each route checks it against the scope it requires.
- Authorization: Bearer <token> header
- Per-route required scope
- Example: list your domains
Signed webhooks
CRM/lead delivery webhooks are HMAC-signed and retried automatically on failure.
- X-Weboptiva-Signature is an HMAC-SHA256 of the raw body
- Failed deliveries retry up to 5 times
- Backoff: 30s, 2m, 10m, 30m
Purge cache via API
Service integrations purge the delivery cache with the tenant API key — list options, then create a purge request.
- Authenticate with the tenant API key
- Full-site, URL, and image purge groups
- Up to 10 paths per request
Use the MCP server
Expose domains, audits, and workflows to AI clients through WebOptiva's MCP server with OAuth-backed access.
- Six tools, from listing domains to running workflows
- Resource URIs for domains, analytics, and security
- OAuth client registration

