Build on Zaps without guessing the contract.
Create Brandfronts and Links, automate workspace operations, and receive signed events through one versioned API.
First authenticated request
Use the one-time API key shown when you create it.
curl --request GET \
--url https://api.zaps.one/api/v1/workspaces \
--header 'Authorization: Bearer zaps_sk_…'Get a key
Create workspace-scoped, permission-limited API keys and signed webhook endpoints.
API access is on Pro
Keys are workspace-scoped and created inside a workspace, so start an account first. Pro and above can create keys and webhook endpoints.
API foundations
Scoped credentials
API keys are workspace-bound, permission-scoped, expirable, and shown only once.
Safe retries
Mutation endpoints document idempotency and optimistic-concurrency headers.
Stable contracts
Versioned paths, bounded inputs, and a consistent success and error envelope.
Rate limits and retries
Limits are enforced per workspace and per endpoint, and the exact ceiling for each route is published in the reference rather than duplicated here.
429 means slow down, not stop
A throttled request returns the standard error envelope with code RATE_LIMITED. Nothing was written.
Retry-After is authoritative
Throttled responses carry a Retry-After header in seconds. Honour it instead of backing off on a guess.
Retries are safe when keyed
Mutations accept Idempotency-Key and replay the original result, so a retry after a timeout cannot double-write.
One contract, every capability
Explore the full surface in the live reference.
The reference is generated from the routes that ship. It documents authentication, request headers, parameters, response envelopes, and error behavior without exposing private operator endpoints.
Read the contract, then make the call.
The interactive reference runs against the same versioned routes your integration will use.