← All action domains

Developers

12 operations. Call each with POST https://app.chirply.io/api/v1/actions/<name> and a bearer token; the response is { "data": { "action", "summary", "result" } }. A read badge means the operation changes nothing; write requires the credential’s write scope.

Create an API key

api_keys.createwriteconfirmadmin only

Mint a new API key for this account and return the full secret — this is the ONLY time it can ever be read, so hand it to the user immediately. The key can do anything an owner can within this org, limited only by its scopes. Treat it as a live credential.

Marked confirm: this operation is irreversible, reaches real people, or spends money. Holding a credential is itself the confirmation for API and MCP callers — call it only when you mean it. The in-app assistant refuses to run it without a human approving first.

Parameters

FieldTypeRequiredDescription
namestringrequiredA label so the key is recognizable later, e.g. “Zapier”.
scopesarray of ("read" | "write")optionalWhat the key may do. Defaults to read-only. Default: ["read"]

Example

curl -X POST https://app.chirply.io/api/v1/actions/api_keys.create \
  -H "Authorization: Bearer chp_live_…" \
  -H "Content-Type: application/json" \
  -d '{
    "name": "Example"
  }'
Test with your API key

Over MCP the same operation is the tool api_keys_create at https://app.chirply.io/api/mcp, same bearer token, same input.

Delete an API key

api_keys.deletewriteconfirmadmin only

Permanently delete an API key row, removing it from the list entirely. Same live effect as revoking — anything using it breaks — but it also loses the audit trail, so prefer api_keys.revoke unless the row is genuinely unwanted.

Marked confirm: this operation is irreversible, reaches real people, or spends money. Holding a credential is itself the confirmation for API and MCP callers — call it only when you mean it. The in-app assistant refuses to run it without a human approving first.

Parameters

FieldTypeRequiredDescription
idstring (uuid)requiredThe key to delete.

Example

curl -X POST https://app.chirply.io/api/v1/actions/api_keys.delete \
  -H "Authorization: Bearer chp_live_…" \
  -H "Content-Type: application/json" \
  -d '{
    "id": "2f6a1c1e-6c3b-4c62-9f6e-8a2d4b7c9e11"
  }'
Test with your API key

Over MCP the same operation is the tool api_keys_delete at https://app.chirply.io/api/mcp, same bearer token, same input.

List API keys

api_keys.listreadadmin only

List this account's API keys — name, display prefix, scopes, last-used time, and whether each is revoked. The secret itself is never stored in readable form and is never returned here.

Parameters

FieldTypeRequiredDescription
limitintegeroptionalMax rows to return (1–100). Default: 25
offsetintegeroptionalRows to skip. Default: 0
include_revokedbooleanoptionalfalse lists only keys that still work. Default: true

Example

curl -X POST https://app.chirply.io/api/v1/actions/api_keys.list \
  -H "Authorization: Bearer chp_live_…" \
  -H "Content-Type: application/json" \
  -d '{
    "limit": 25,
    "offset": 0
  }'
Test with your API key

Over MCP the same operation is the tool api_keys_list at https://app.chirply.io/api/mcp, same bearer token, same input.

Revoke an API key

api_keys.revokewriteconfirmadmin only

Revoke an API key immediately. Any integration authenticating with it starts failing on its next request, and the key can never be un-revoked.

Marked confirm: this operation is irreversible, reaches real people, or spends money. Holding a credential is itself the confirmation for API and MCP callers — call it only when you mean it. The in-app assistant refuses to run it without a human approving first.

Parameters

FieldTypeRequiredDescription
idstring (uuid)requiredThe key to revoke.

Example

curl -X POST https://app.chirply.io/api/v1/actions/api_keys.revoke \
  -H "Authorization: Bearer chp_live_…" \
  -H "Content-Type: application/json" \
  -d '{
    "id": "2f6a1c1e-6c3b-4c62-9f6e-8a2d4b7c9e11"
  }'
Test with your API key

Over MCP the same operation is the tool api_keys_revoke at https://app.chirply.io/api/mcp, same bearer token, same input.

List Connected Apps

connected_apps.listreadadmin only

List the third-party applications connected to this account over OAuth — which app, who approved it, what it is allowed to do, and when it last made a request. Tokens themselves are stored only as hashes and are never returned.

Parameters

FieldTypeRequiredDescription
limitintegeroptionalMax rows to return (1–100). Default: 25
offsetintegeroptionalRows to skip. Default: 0
include_revokedbooleanoptionaltrue also lists connections that have already been disconnected. Default: false

Example

curl -X POST https://app.chirply.io/api/v1/actions/connected_apps.list \
  -H "Authorization: Bearer chp_live_…" \
  -H "Content-Type: application/json" \
  -d '{
    "limit": 25,
    "offset": 0
  }'
Test with your API key

Over MCP the same operation is the tool connected_apps_list at https://app.chirply.io/api/mcp, same bearer token, same input.

Disconnect an App

connected_apps.revokewriteconfirmadmin only

Disconnect a third-party application from this account. Its access stops immediately and every token it holds is destroyed, so any automation running through it — Zaps, scripts, scheduled syncs — stops working at once and cannot be resumed without the owner approving the connection again. There is no undo.

Marked confirm: this operation is irreversible, reaches real people, or spends money. Holding a credential is itself the confirmation for API and MCP callers — call it only when you mean it. The in-app assistant refuses to run it without a human approving first.

Parameters

FieldTypeRequiredDescription
idstring (uuid)requiredThe connection id, from connected_apps.list.

Example

curl -X POST https://app.chirply.io/api/v1/actions/connected_apps.revoke \
  -H "Authorization: Bearer chp_live_…" \
  -H "Content-Type: application/json" \
  -d '{
    "id": "2f6a1c1e-6c3b-4c62-9f6e-8a2d4b7c9e11"
  }'
Test with your API key

Over MCP the same operation is the tool connected_apps_revoke at https://app.chirply.io/api/mcp, same bearer token, same input.

List webhook subscriptions

webhooks.listreadadmin only

List this account's outbound webhook subscriptions — each event × endpoint pair with its status and creation time — plus the full catalog of event names that can be subscribed to. Signing secrets are never returned here.

Parameters

FieldTypeRequiredDescription
limitintegeroptionalMax rows to return (1–100). Default: 25
offsetintegeroptionalRows to skip. Default: 0

Example

curl -X POST https://app.chirply.io/api/v1/actions/webhooks.list \
  -H "Authorization: Bearer chp_live_…" \
  -H "Content-Type: application/json" \
  -d '{
    "limit": 25,
    "offset": 0
  }'
Test with your API key

Over MCP the same operation is the tool webhooks_list at https://app.chirply.io/api/mcp, same bearer token, same input.

View webhook deliveries

webhooks.list_deliveriesreadadmin only

The delivery log for one webhook subscription, newest first: each attempt's status (pending, delivered, failed, or dead once retries run out), attempt count, last error, and timestamps — for debugging an endpoint that isn't receiving events. Read-only.

Parameters

FieldTypeRequiredDescription
idstring (uuid)requiredThe webhook subscription whose deliveries to list.
limitintegeroptionalMax rows to return (1–100). Default: 25
offsetintegeroptionalRows to skip. Default: 0

Example

curl -X POST https://app.chirply.io/api/v1/actions/webhooks.list_deliveries \
  -H "Authorization: Bearer chp_live_…" \
  -H "Content-Type: application/json" \
  -d '{
    "id": "2f6a1c1e-6c3b-4c62-9f6e-8a2d4b7c9e11"
  }'
Test with your API key

Over MCP the same operation is the tool webhooks_list_deliveries at https://app.chirply.io/api/mcp, same bearer token, same input.

Read the event stream

webhooks.read_eventsreadadmin only

Read the platform events this account's webhook subscriptions have produced — oldest first, with each event's full payload — and walk forward with a cursor. This is the PULL side of webhooks, for a caller that cannot receive a POST: an AI agent connected over MCP has no HTTPS endpoint to deliver to, so it asks what happened since it last looked instead. Subscribe with webhooks.subscribe first (an endpoint URL is still required to register the subscription); every event that matches then shows up here whether or not that endpoint answered. Pass the previous reply's next_cursor as `after` to continue without re-reading or skipping. Read-only and costs nothing.

Parameters

FieldTypeRequiredDescription
afterstringoptionalThe `next_cursor` from your previous call, to read only what has happened since. Omit to start at the oldest retained event. An ISO timestamp also works.
eventstringoptionalOnly this event name, e.g. "contact_created". Call webhooks.list for the full catalog of event names.
subscription_idstring (uuid)optionalOnly events produced by this one subscription.
limitintegeroptionalMax events to return (1-100). Default: 25

Example

curl -X POST https://app.chirply.io/api/v1/actions/webhooks.read_events \
  -H "Authorization: Bearer chp_live_…" \
  -H "Content-Type: application/json" \
  -d '{
    "after": "example",
    "event": "example"
  }'
Test with your API key

Over MCP the same operation is the tool webhooks_read_events at https://app.chirply.io/api/mcp, same bearer token, same input.

Send test event

webhooks.send_testwriteconfirmadmin only

Send one signed TEST delivery of a subscription's event to its endpoint right now, through the same signing and POST path as real deliveries, and record the result in its delivery log. Order events (order_paid, order_refunded, order_cancelled) carry a realistic EXAMPLE order — every line with SKU, variant, quantity and amounts, and a made-up buyer — so an integration can be built before a real sale happens; other events carry a minimal placeholder context. The payload is marked "test": true and contains no real account data. It is an outward HTTP request to a third-party URL, attempted once with no retries.

Marked confirm: this operation is irreversible, reaches real people, or spends money. Holding a credential is itself the confirmation for API and MCP callers — call it only when you mean it. The in-app assistant refuses to run it without a human approving first.

Parameters

FieldTypeRequiredDescription
idstring (uuid)requiredThe webhook subscription to send a test delivery to.

Example

curl -X POST https://app.chirply.io/api/v1/actions/webhooks.send_test \
  -H "Authorization: Bearer chp_live_…" \
  -H "Content-Type: application/json" \
  -d '{
    "id": "2f6a1c1e-6c3b-4c62-9f6e-8a2d4b7c9e11"
  }'
Test with your API key

Over MCP the same operation is the tool webhooks_send_test at https://app.chirply.io/api/mcp, same bearer token, same input.

Subscribe a webhook

webhooks.subscribewriteconfirmadmin only

Register an HTTPS endpoint to receive platform events as they happen — the automation trigger names (contact_created, message_received, deal_won, invoice_paid, …). From then on this account POSTs every occurrence of the subscribed events to that URL, HMAC-signed, with retries — account data (contact ids, event context) flows to whoever controls the endpoint until the subscription is deleted. Returns the signing secret exactly ONCE; it cannot be read back, so hand it to the user immediately.

Marked confirm: this operation is irreversible, reaches real people, or spends money. Holding a credential is itself the confirmation for API and MCP callers — call it only when you mean it. The in-app assistant refuses to run it without a human approving first.

Parameters

FieldTypeRequiredDescription
urlstringrequiredAbsolute HTTPS URL that will receive the event POSTs, e.g. https://hooks.example.com/events.
eventsstring[]requiredEvent names to subscribe to — the automation trigger names, e.g. ['contact_created','message_received']. List valid names with webhooks.list.

Example

curl -X POST https://app.chirply.io/api/v1/actions/webhooks.subscribe \
  -H "Authorization: Bearer chp_live_…" \
  -H "Content-Type: application/json" \
  -d '{
    "url": "https://example.com",
    "events": [
      "example"
    ]
  }'
Test with your API key

Over MCP the same operation is the tool webhooks_subscribe at https://app.chirply.io/api/mcp, same bearer token, same input.

Delete a webhook subscription

webhooks.unsubscribewriteconfirmadmin only

Delete one outbound webhook subscription. Event deliveries to its endpoint stop immediately and its delivery log is removed with it. This cannot be undone — re-subscribing mints a NEW signing secret, so the integration on the other end must be reconfigured.

Marked confirm: this operation is irreversible, reaches real people, or spends money. Holding a credential is itself the confirmation for API and MCP callers — call it only when you mean it. The in-app assistant refuses to run it without a human approving first.

Parameters

FieldTypeRequiredDescription
idstring (uuid)requiredThe webhook subscription to delete.

Example

curl -X POST https://app.chirply.io/api/v1/actions/webhooks.unsubscribe \
  -H "Authorization: Bearer chp_live_…" \
  -H "Content-Type: application/json" \
  -d '{
    "id": "2f6a1c1e-6c3b-4c62-9f6e-8a2d4b7c9e11"
  }'
Test with your API key

Over MCP the same operation is the tool webhooks_unsubscribe at https://app.chirply.io/api/mcp, same bearer token, same input.

The machine-readable version of this page is GET https://app.chirply.io/api/v1/actions?domain=developers — same operations, with full JSON Schemas. Authentication, errors and rate limits are covered in the API documentation home.