Skip to content
DocsGo to Dashboard

Developers

Public API & webhooks

Authenticate server-to-server calls with a scoped service-account token, and receive signed webhook deliveries for CRM/lead events.

Service account tokens

Create a scoped, expiring bearer token for server-to-server access instead of sharing a user's session.

  • Scopes: read, write, webhooks
  • Optional expiry in days
  • Rotate or revoke without downtime for other tokens

Authenticating public API requests

Send the token as a standard bearer credential; each route checks it against the scope it requires.

  • Authorization: Bearer <token> header
  • Per-route required scope
  • Example: list your domains

Signed webhooks

CRM/lead delivery webhooks are HMAC-signed and retried automatically on failure.

  • X-Weboptiva-Signature is an HMAC-SHA256 of the raw body
  • Failed deliveries retry up to 5 times
  • Backoff: 30s, 2m, 10m, 30m

Purge cache via API

Service integrations purge the delivery cache with the tenant API key — list options, then create a purge request.

  • Authenticate with the tenant API key
  • Full-site, URL, and image purge groups
  • Up to 10 paths per request

Use the MCP server

Expose domains, audits, and workflows to AI clients through WebOptiva's MCP server with OAuth-backed access.

  • Six tools, from listing domains to running workflows
  • Resource URIs for domains, analytics, and security
  • OAuth client registration