← All action domains

Providers

4 operations. Call each with POST https://app.chirply.io/api/v1/actions/<name> and a bearer token; the response is { "data": { "action", "summary", "result" } }. A read badge means the operation changes nothing; write requires the credential’s write scope.

Connectable API catalog

providers.catalogreadadmin only

List every third-party API this account's own agents can reach through Chirply once the account is connected — each provider's id, the exact hosts it may be called on, a link to its API reference, and how to build a correct path. Also names the providers that are connectable but NOT reachable by passthrough, with the reason. Read this before calling providers.request so you use the right provider id and path shape. Prefer a curated capability (meta.*, telephony.*, campaigns.*) whenever one exists: those validate input, respect plan limits, and write results back into the CRM, which passthrough does not. Read-only and costs nothing.

Parameters

No parameters — POST an empty body.

Example

curl -X POST https://app.chirply.io/api/v1/actions/providers.catalog \
  -H "Authorization: Bearer chp_live_…" \
  -H "Content-Type: application/json" \
  -d '{}'
Test with your API key

Over MCP the same operation is the tool providers_catalog at https://app.chirply.io/api/mcp, same bearer token, same input.

Connected provider APIs

providers.connectedreadadmin only

Report which third-party accounts THIS account has actually connected, and for each one whether its API can be reached through passthrough right now — including why not, when it cannot (the provider isn't wired for passthrough, or its credentials come from the parent agency's pooled account rather than this account's own). Never returns any credential, only which ones exist. Use it to find out what an agent can do here before trying a call. Read-only and costs nothing.

Parameters

No parameters — POST an empty body.

Example

curl -X POST https://app.chirply.io/api/v1/actions/providers.connected \
  -H "Authorization: Bearer chp_live_…" \
  -H "Content-Type: application/json" \
  -d '{}'
Test with your API key

Over MCP the same operation is the tool providers_connected at https://app.chirply.io/api/mcp, same bearer token, same input.

Read from a connected API

providers.readreadadmin only

Make a read-only (GET or HEAD) call to a third-party API using the credentials this account already connected to Chirply — Meta Graph, Twilio, Stripe, Supabase, Mailgun, Klaviyo, Cloudflare and the rest. The credential is attached server-side and is never returned. Use this to pull data an agent needs: ad account performance, a Stripe customer, Twilio call logs, a Supabase project list. Nothing is written and nothing is charged beyond whatever the provider bills for a read (most bill nothing; Outscraper, fal.ai, Replicate and OpenRouter charge per request even for reads). Only hosts on the provider's allowlist can be reached, and redirects are never followed.

Parameters

FieldTypeRequiredDescription
providerstringrequiredWhich connected provider to call, e.g. "meta", "twilio", "stripe", "supabase". Call providers.catalog for the exact list, each provider's allowed hosts, and its API docs.
pathstringrequiredThe API path on that provider, e.g. "/v26.0/me/adaccounts" for Meta or "/v1/customers" for Stripe. A PATH, never a full URL — the host comes from the provider's allowlist so a stored credential can never be sent elsewhere. A query string here is merged with `query`.
method"GET" | "HEAD"optionalGET (default) or HEAD. Use providers.request for anything that changes data. Default: "GET"
hoststringoptionalOptional. Pick a non-default host from the SAME provider's allowlist (e.g. "lookups.twilio.com" instead of "api.twilio.com"). For a provider whose accounts are per-account — Shopify, where each connected store is its own host — this names WHICH account to call, e.g. "acme.myshopify.com"; omit it and the first connected one is used. Call providers.connected for the list. Anything not on the list is refused.
querymap of string → objectoptionalQuery-string parameters, e.g. { fields: "name,account_status", limit: 25 }.
headersmap of string → stringoptionalExtra request headers. Authentication is attached for you — Authorization, Cookie, Host, and forwarding headers are dropped if you send them, and the reply lists what was dropped.

Example

curl -X POST https://app.chirply.io/api/v1/actions/providers.read \
  -H "Authorization: Bearer chp_live_…" \
  -H "Content-Type: application/json" \
  -d '{
    "provider": "example",
    "path": "example"
  }'
Test with your API key

Over MCP the same operation is the tool providers_read at https://app.chirply.io/api/mcp, same bearer token, same input.

Call a connected API

providers.requestwriteconfirmadmin only

Make any HTTP call — including POST, PUT, PATCH and DELETE — to a third-party API using the credentials this account already connected to Chirply. This acts AS the account on its own accounts, so it can do anything those credentials can: publish a Facebook ad and start it spending, send an SMS billed to the org's Twilio account, charge a card on its Stripe account, or delete records in its Supabase project. There is no undo, no confirmation from the provider, and no Chirply-side spend limit — the cost lands on the account's own provider bills. Prefer a curated capability (meta.*, telephony.*, campaigns.*) when one exists; those validate input, respect plan limits, and write results back into the CRM. Only hosts on the provider's allowlist can be reached, credentials are attached server-side and never returned, and redirects are never followed. Every call is written to the account's audit log.

Marked confirm: this operation is irreversible, reaches real people, or spends money. Holding a credential is itself the confirmation for API and MCP callers — call it only when you mean it. The in-app assistant refuses to run it without a human approving first.

Parameters

FieldTypeRequiredDescription
providerstringrequiredWhich connected provider to call, e.g. "meta", "twilio", "stripe", "supabase". Call providers.catalog for the exact list, each provider's allowed hosts, and its API docs.
pathstringrequiredThe API path on that provider, e.g. "/v26.0/me/adaccounts" for Meta or "/v1/customers" for Stripe. A PATH, never a full URL — the host comes from the provider's allowlist so a stored credential can never be sent elsewhere. A query string here is merged with `query`.
method"GET" | "HEAD" | "POST" | "PUT" | "PATCH" | "DELETE"optionalHTTP method. POST/PUT/PATCH/DELETE change the provider's data for real. Default: "POST"
hoststringoptionalOptional. Pick a non-default host from the SAME provider's allowlist (e.g. "lookups.twilio.com" instead of "api.twilio.com"). For a provider whose accounts are per-account — Shopify, where each connected store is its own host — this names WHICH account to call, e.g. "acme.myshopify.com"; omit it and the first connected one is used. Call providers.connected for the list. Anything not on the list is refused.
querymap of string → objectoptionalQuery-string parameters, e.g. { fields: "name,account_status", limit: 25 }.
bodyanyoptionalJSON request body, sent as application/json. Use `form` instead for Twilio, Stripe and Mailgun, which require form encoding. Cannot be combined with `form`.
formmap of string → objectoptionalForm-encoded request body, e.g. { To: "+15551234567", Body: "hi" }. What Twilio, Stripe and Mailgun expect. Cannot be combined with `body`.
headersmap of string → stringoptionalExtra request headers. Authentication is attached for you — Authorization, Cookie, Host, and forwarding headers are dropped if you send them, and the reply lists what was dropped.

Example

curl -X POST https://app.chirply.io/api/v1/actions/providers.request \
  -H "Authorization: Bearer chp_live_…" \
  -H "Content-Type: application/json" \
  -d '{
    "provider": "example",
    "path": "example"
  }'
Test with your API key

Over MCP the same operation is the tool providers_request at https://app.chirply.io/api/mcp, same bearer token, same input.

The machine-readable version of this page is GET https://app.chirply.io/api/v1/actions?domain=providers — same operations, with full JSON Schemas. Authentication, errors and rate limits are covered in the API documentation home.