Authentication
Every request needs an API key in the Authorization header:
Authorization: Bearer bobb_sk_...Create a key from your account's Settings → API Keys page. A key is scoped read or write (write implies read) and can be revoked at any time. The raw secret is shown exactly once, at creation — only its hash is stored, so losing it means creating a new key.
Base URL
https://trybobb.com/api/v1Rate limits
Requests are limited per API key and per source IP. Limits are enforced in the database, so they hold across every server instance — not just the one that happened to handle your request. A rate-limited request gets a 429 with a Retry-After header.
Endpoints
GET /contacts
List contacts in your account's audience. Paginated (limit, offset, default 25, max 100).
POST /contacts
Create or attach a contact by subscribing it to one of your lists. Body: { email, list, first_name?, fields? }.
GET /contacts/:id
Get a single contact, including its custom field values.
PATCH /contacts/:id
Update a contact's name, company, or custom fields.
POST /subscriptions
Subscribe an address to one of your lists. Body: { email, list, first_name?, fields? }.
POST /subscriptions/unsubscribe
Unsubscribe an address from one of your lists. Body: { email, list }.
GET /lists
List your lists.
GET /forms
List your forms.
GET /custom-fields
List your custom field definitions.
GET /broadcasts
List your broadcasts. Paginated.
GET /broadcasts/:id
Get a single broadcast.
GET /broadcasts/:id/status
Get a broadcast's send status (status, recipients, scheduled_at, sent_at).
OpenAPI spec
A machine-readable spec is served at /api/v1/openapi — paste it into Postman, Zapier, or any OpenAPI-aware tool.