Create and list apps, read and update per-app settings and platform credentials, and rotate REST and SDK keys. Rotation has no grace window — the old value stops working on the very next request.
List all apps
Every app on the server, across every workspace, with subscriber count, CTR and monthly active users (both rounded and exact, so the figure can be reconciled against your own query).
Global operator key only. There is no workspace-scoped version of this route: a per-app REST key knows one app, and listing a workspace's apps is a console operation that resolves the workspace from the signed-in session.
List all apps › Responses
Every app with subscriber, CTR and MAU figures
Create an app
Creates an app from a slug (id, or slug), optionally with a display
name, and mints its key set. Calling it again with an existing slug returns that app rather
than failing.
Global operator key only, and the app lands in the default workspace — a REST call carries no console session and therefore no workspace to put it in. Creating an app inside a specific workspace is a console action.
Create an app › Request Body
App slug; supply id or slug.
Display name; defaults from the slug.
Alias of id.
Create an app › Responses
The app row, including its freshly minted keys
Read the app's audit log
Who did what on this app, newest first: console actions, REST calls and MCP tool
calls (source=mcp, action=<tool name>). Filter with source and action; limit is capped at
1000. Network metadata — IP address, user agent, country — is deliberately not returned here:
this route answers "what was done", and the console's own audit view is where a network fact is
looked up by someone who can be held to it. The rows name operators, so this read needs a
full-scope key, like /keys.
path Parameters
app_idquery Parameters
limitsourceactionRead the app's audit log › Responses
Audit entries, newest first
List API keys
Metadata for every key on one app. Secret values are omitted by default.
include_values=true is a temporary compatibility option through 2026-10-23 UTC;
afterward it returns 410. New and rotated secret values are returned once by their write calls.
A disabled or expired key remains in this list but cannot authenticate.
Each row carries a scope: full, which is what a REST key has always meant, or read,
which may read reports, audiences and settings but cannot send, schedule, cancel or change
anything — including this route, which reveals key values.
path Parameters
app_idquery Parameters
include_valuesList API keys › Responses
The app's key rows
Rotate an API key
Create a replacement for a key ID or an active key kind. The new secret is
returned once. The previous REST value remains valid for 24 hours; a previous SDK value
remains valid for seven days. Its expiry is returned as old_key_expires_at.
Disable a specific key early with PATCH /keys/{key_id} if rollout is complete.
path Parameters
app_idkindRotate an API key › Responses
The new key value, shown once, and old-key expiry
Upload a reviewed app manifest
Stores only the consent-filtered manifest produced after OpenPush Scan review.
path Parameters
app_idUpload a reviewed app manifest › Request Body
Upload a reviewed app manifest › Responses
Successful Response
Read app settings
Quiet hours, frequency caps, link tracking, delivery pacing, and Android
channel configuration, plus
three things a settings page always needs next: per-app platform readiness (which of
FCM, APNs and web push this app can actually send on), which optional data categories the
app collects and how many rows of each are already stored, and the server-wide IP storage
mode (full, truncated or off).
identity_verification is reported here but cannot be changed through the API — see the
PATCH route.
path Parameters
app_idRead app settings › Responses
Settings, per-app platform readiness, and collection state
Update app settings
Updates quiet hours, frequency caps, link tracking and initial delivery
pacing. Collection switches are accepted either flat
(collect_ad_id) or nested (collection: {ad_id: true}), because a console form posts one
shape and an integration posts back the object it read.
Turning a collection switch off erases what it collected. The purge runs in the same call and the response reports the row counts under
purged. There is no undo.
identity_verification is deliberately not accepted here — changing it is a console
action. A patch that touches none of the accepted fields is a 400.
path Parameters
app_idUpdate app settings › Request Body
Advertising-id collection switch.
Email collection switch.
Location collection switch.
Nested ad_id, location, and email collection switches.
Provider-accepted sends per device per window; 0 disables.
Frequency-cap window in hours.
Add UTM tags to HTTP(S) launch URLs.
Turn quiet hours on or off.
End of the allowed daily window, HH:MM device-local.
Start of the allowed daily window, HH:MM device-local.
Pace initial delivery in minute-sized waves.
Maximum initial deliveries queued each minute.
Fixed campaign value; blank uses the message name.
UTM medium value.
UTM source value.
Update app settings › Responses
The settings after the update, with any purge counts
Accept Suggestion
path Parameters
app_idsuggestion_idAccept Suggestion › Request Body optional
For in-app recommendations, create a reusable template instead of a draft message.
Accept Suggestion › Responses
Successful Response