API documentation

Pull your data over REST and get real-time events via signed webhooks. Included in every plan at no extra cost. You create the API key yourself in the portal.

Authentication

Create an API key in the portal (app.chattassistent.se → Notifications → Create API key). The key is shown once — we only store a hash. Send it as a Bearer token:

Authorization: Bearer ca_live_...

Base URL

https://fsrdagxhznwizwmsbmxx.supabase.co/functions/v1/api

Endpoints (v1 — read)

GET /v1/leads

Your leads: name, email, phone, interest, status, conversation id, created.

GET /v1/bookings

Your bookings: name, phone, email, subject, status, start/end, staff member, created/cancelled.

GET /v1/conversations

Your conversations: session, domain, language, message count, CSAT rating, start/last message.

Parameters (all endpoints)

  • limit — maximum rows (1–100, default 50)
  • offset — skip N rows (pagination)
  • since — ISO date, only rows created after it (e.g. 2026-08-01)

Example

curl -H "Authorization: Bearer ca_live_DIN_NYCKEL" \
  "https://fsrdagxhznwizwmsbmxx.supabase.co/functions/v1/api/v1/leads?limit=10&since=2026-08-01"

Response:

{
  "object": "list",
  "resource": "leads",
  "count": 2,
  "limit": 10,
  "offset": 0,
  "data": [
    {
      "id": "…",
      "visitor_name": "Anna Andersson",
      "visitor_email": "anna@example.se",
      "visitor_phone": "+46701234567",
      "interest": "Vill boka demo",
      "status": "new",
      "conversation_id": "…",
      "created_at": "2026-08-20T09:15:00+00:00"
    }
  ]
}

Webhooks (real-time, outgoing)

For real-time events — new lead, new booking, cancelled booking — you enable webhooks in the portal (Notifications → Webhooks). We POST JSON to your endpoint, signed with HMAC-SHA256:

POST https://er-endpoint.se/webhook
X-Chattassistent-Event: lead.created
X-Chattassistent-Signature: sha256=<hex>

{
  "event": "lead.created",
  "tenant_id": "…",
  "occurred_at": "2026-08-20T09:15:00+00:00",
  "data": { "id": "…", "name": "…", "email": "…", "phone": "…", "interest": "…" }
}

Verify the signature by running HMAC-SHA256 over the whole request body with your signing key (shown in the portal) and comparing. Zapier and Make don't need to verify — just paste in your Catch Hook / Custom webhook URL.

Fair use & versioning

  • ✔ The API is included in every plan at no extra cost. Keep your call rate reasonable (don't poll more often than once a minute — use webhooks for real time).
  • ✔ v1 is read-only. Breaking changes only arrive in new versions (/v2) — v1 stays stable.
  • ✔ Questions or needs (writing, more fields)? info@chattassistent.se

Common questions

What can I pull via the API?

v1 is read-only: your leads (GET /v1/leads), bookings (GET /v1/bookings) and conversations (GET /v1/conversations) — always only your own tenant's data, governed by the API key. Real-time events are pushed via webhooks instead (new lead, new booking, cancellation).

How do I get an API key?

Log in at app.chattassistent.se, go to Notifications and click Create API key. The key is shown exactly once — we only store a hash of it, so copy it straight away. A lost key is replaced by creating a new one and revoking the old.

Does the API cost anything?

No — API access is included in every plan at no extra cost.

Can I write data via the API?

Not in v1 — writing happens through the chat, the portal and the receptionist. If you need to push data in from your own systems, get in touch at info@chattassistent.se and we'll look at what you need.