12 operations. Call each with POST https://app.chirply.io/api/v1/actions/<name> and a bearer token; the response is { "data": { "action", "summary", "result" } }. A read badge means the operation changes nothing; write requires the credential’s write scope.
Create an API key
api_keys.createwriteconfirmadmin only
Mint a new API key for this account and return the full secret — this is the ONLY time it can ever be read, so hand it to the user immediately. The key can do anything an owner can within this org, limited only by its scopes. Treat it as a live credential.
Marked confirm: this operation is irreversible, reaches real people, or spends money. Holding a credential is itself the confirmation for API and MCP callers — call it only when you mean it. The in-app assistant refuses to run it without a human approving first.
Parameters
Field
Type
Required
Description
name
string
required
A label so the key is recognizable later, e.g. “Zapier”.
scopes
array of ("read" | "write")
optional
What the key may do. Defaults to read-only. Default: ["read"]
Over MCP the same operation is the tool api_keys_create at https://app.chirply.io/api/mcp, same bearer token, same input.
Delete an API key
api_keys.deletewriteconfirmadmin only
Permanently delete an API key row, removing it from the list entirely. Same live effect as revoking — anything using it breaks — but it also loses the audit trail, so prefer api_keys.revoke unless the row is genuinely unwanted.
Marked confirm: this operation is irreversible, reaches real people, or spends money. Holding a credential is itself the confirmation for API and MCP callers — call it only when you mean it. The in-app assistant refuses to run it without a human approving first.
Over MCP the same operation is the tool api_keys_delete at https://app.chirply.io/api/mcp, same bearer token, same input.
List API keys
api_keys.listreadadmin only
List this account's API keys — name, display prefix, scopes, last-used time, and whether each is revoked. The secret itself is never stored in readable form and is never returned here.
Parameters
Field
Type
Required
Description
limit
integer
optional
Max rows to return (1–100). Default: 25
offset
integer
optional
Rows to skip. Default: 0
include_revoked
boolean
optional
false lists only keys that still work. Default: true
Over MCP the same operation is the tool api_keys_list at https://app.chirply.io/api/mcp, same bearer token, same input.
Revoke an API key
api_keys.revokewriteconfirmadmin only
Revoke an API key immediately. Any integration authenticating with it starts failing on its next request, and the key can never be un-revoked.
Marked confirm: this operation is irreversible, reaches real people, or spends money. Holding a credential is itself the confirmation for API and MCP callers — call it only when you mean it. The in-app assistant refuses to run it without a human approving first.
Over MCP the same operation is the tool api_keys_revoke at https://app.chirply.io/api/mcp, same bearer token, same input.
List Connected Apps
connected_apps.listreadadmin only
List the third-party applications connected to this account over OAuth — which app, who approved it, what it is allowed to do, and when it last made a request. Tokens themselves are stored only as hashes and are never returned.
Parameters
Field
Type
Required
Description
limit
integer
optional
Max rows to return (1–100). Default: 25
offset
integer
optional
Rows to skip. Default: 0
include_revoked
boolean
optional
true also lists connections that have already been disconnected. Default: false
Over MCP the same operation is the tool connected_apps_list at https://app.chirply.io/api/mcp, same bearer token, same input.
Disconnect an App
connected_apps.revokewriteconfirmadmin only
Disconnect a third-party application from this account. Its access stops immediately and every token it holds is destroyed, so any automation running through it — Zaps, scripts, scheduled syncs — stops working at once and cannot be resumed without the owner approving the connection again. There is no undo.
Marked confirm: this operation is irreversible, reaches real people, or spends money. Holding a credential is itself the confirmation for API and MCP callers — call it only when you mean it. The in-app assistant refuses to run it without a human approving first.
Over MCP the same operation is the tool connected_apps_revoke at https://app.chirply.io/api/mcp, same bearer token, same input.
List webhook subscriptions
webhooks.listreadadmin only
List this account's outbound webhook subscriptions — each event × endpoint pair with its status and creation time — plus the full catalog of event names that can be subscribed to. Signing secrets are never returned here.
Over MCP the same operation is the tool webhooks_list at https://app.chirply.io/api/mcp, same bearer token, same input.
View webhook deliveries
webhooks.list_deliveriesreadadmin only
The delivery log for one webhook subscription, newest first: each attempt's status (pending, delivered, failed, or dead once retries run out), attempt count, last error, and timestamps — for debugging an endpoint that isn't receiving events. Read-only.
Parameters
Field
Type
Required
Description
id
string (uuid)
required
The webhook subscription whose deliveries to list.
Over MCP the same operation is the tool webhooks_list_deliveries at https://app.chirply.io/api/mcp, same bearer token, same input.
Read the event stream
webhooks.read_eventsreadadmin only
Read the platform events this account's webhook subscriptions have produced — oldest first, with each event's full payload — and walk forward with a cursor. This is the PULL side of webhooks, for a caller that cannot receive a POST: an AI agent connected over MCP has no HTTPS endpoint to deliver to, so it asks what happened since it last looked instead. Subscribe with webhooks.subscribe first (an endpoint URL is still required to register the subscription); every event that matches then shows up here whether or not that endpoint answered. Pass the previous reply's next_cursor as `after` to continue without re-reading or skipping. Read-only and costs nothing.
Parameters
Field
Type
Required
Description
after
string
optional
The `next_cursor` from your previous call, to read only what has happened since. Omit to start at the oldest retained event. An ISO timestamp also works.
event
string
optional
Only this event name, e.g. "contact_created". Call webhooks.list for the full catalog of event names.
Over MCP the same operation is the tool webhooks_read_events at https://app.chirply.io/api/mcp, same bearer token, same input.
Send test event
webhooks.send_testwriteconfirmadmin only
Send one signed TEST delivery of a subscription's event to its endpoint right now, through the same signing and POST path as real deliveries, and record the result in its delivery log. Order events (order_paid, order_refunded, order_cancelled) carry a realistic EXAMPLE order — every line with SKU, variant, quantity and amounts, and a made-up buyer — so an integration can be built before a real sale happens; other events carry a minimal placeholder context. The payload is marked "test": true and contains no real account data. It is an outward HTTP request to a third-party URL, attempted once with no retries.
Marked confirm: this operation is irreversible, reaches real people, or spends money. Holding a credential is itself the confirmation for API and MCP callers — call it only when you mean it. The in-app assistant refuses to run it without a human approving first.
Parameters
Field
Type
Required
Description
id
string (uuid)
required
The webhook subscription to send a test delivery to.
Over MCP the same operation is the tool webhooks_send_test at https://app.chirply.io/api/mcp, same bearer token, same input.
Subscribe a webhook
webhooks.subscribewriteconfirmadmin only
Register an HTTPS endpoint to receive platform events as they happen — the automation trigger names (contact_created, message_received, deal_won, invoice_paid, …). From then on this account POSTs every occurrence of the subscribed events to that URL, HMAC-signed, with retries — account data (contact ids, event context) flows to whoever controls the endpoint until the subscription is deleted. Returns the signing secret exactly ONCE; it cannot be read back, so hand it to the user immediately.
Marked confirm: this operation is irreversible, reaches real people, or spends money. Holding a credential is itself the confirmation for API and MCP callers — call it only when you mean it. The in-app assistant refuses to run it without a human approving first.
Parameters
Field
Type
Required
Description
url
string
required
Absolute HTTPS URL that will receive the event POSTs, e.g. https://hooks.example.com/events.
events
string[]
required
Event names to subscribe to — the automation trigger names, e.g. ['contact_created','message_received']. List valid names with webhooks.list.
Over MCP the same operation is the tool webhooks_subscribe at https://app.chirply.io/api/mcp, same bearer token, same input.
Delete a webhook subscription
webhooks.unsubscribewriteconfirmadmin only
Delete one outbound webhook subscription. Event deliveries to its endpoint stop immediately and its delivery log is removed with it. This cannot be undone — re-subscribing mints a NEW signing secret, so the integration on the other end must be reconfigured.
Marked confirm: this operation is irreversible, reaches real people, or spends money. Holding a credential is itself the confirmation for API and MCP callers — call it only when you mean it. The in-app assistant refuses to run it without a human approving first.