Server API

Base URL: https://app.try-signal.com. Authenticate with a secret key (sig_sk_…, created under Settings → Install):

curl https://app.try-signal.com/v1/admin/integrations \
  -H "Authorization: Bearer sig_sk_live_…"

Keep secret keys on your server. Requests and responses are JSON. Errors look like { "error": "code", "message": "…" }; validation errors are 400 { "error": "invalid_request", "issues": ["…"] }. Requests are limited to 600 a minute.

Report an outcome

Tell Signal what happened after the visit, so Insights can show which channels, pages and offers bring deals.

POST /v1/outcomes

{ "visitorId": "vis_…", "type": "won", "value": 4800, "currency": "EUR" }
Field
visitorId From window.signal.visitorId, a webhook, or the dashboard.
type won, booked, form_submitted or unsubscribed.
value, currency Optional deal value (currency is a 3-letter code).
offerId, routeId, data Optional.

Response: { "id": "out_…" }. 404 unknown_visitor if the visitor doesn't exist.

Tip: save window.signal.visitorId with a lead or order in your own system, so you can report its outcome later.

Publish a configuration

POST /v1/admin/config with the configuration itself as the body. It's validated, stored as a new version and made active.

Response: { "version": 12, "configHash": "…" }, or 400 { "error": "invalid_config", "issues": ["…"] }.

A visitor's data

Request Does
GET /v1/visitors/:id/export Everything stored about the visitor (sessions, events, answers, contact details and consents, offers, outcomes, emails, forms, chat), for a data request.
DELETE /v1/visitors/:id Deletes the visitor and all their data. Response: { "deleted": true }.

Integrations

Request Does
GET /v1/admin/integrations Lists integrations: name, provider, settings, hasSecrets, health, lastError.
PUT /v1/admin/integrations/:name Creates or replaces one. Secrets are write-only.
// PUT /v1/admin/integrations/crm
{ "provider": "webhook", "settings": { "url": "https://example.com/signal" }, "secrets": { "signingSecret": "whsec_…" } }

// PUT /v1/admin/integrations/email
{ "provider": "resend", "settings": { "from": "Acme <hello@acme.com>" }, "secrets": { "apiKey": "re_…" } }

Providers: resend (email; settings.from, secrets.apiKey, optional secrets.webhookSecret for delivery updates), calendly (secrets.signingKey, marks bookings), and webhook (see Webhooks).

The browser API

The JavaScript client talks to /v1/sessions, /v1/events, /v1/next and a few more with the publishable key, only from your allowed domains. Use the JavaScript API rather than calling these directly; they may change.