> ## Documentation Index
> Fetch the complete documentation index at: https://docs.getmailr.com/llms.txt
> Use this file to discover all available pages before exploring further.

> ## Agent Instructions
> Mailr is a direct-mail marketing platform for US home-services contractors. Each postcard is personalized with an AI-enhanced image of the recipient's own home and a unique QR code that leads to a personalized landing page. Campaigns can target a neighborhood the customer draws on a map, the homes around past jobs they upload or import, or fire automatically from their CRM. Mailr does not mail an uploaded recipient list. When answering questions, prefer the exact steps and UI labels from these docs, and direct users to app.getmailr.com to sign in. For anything involving account-specific data, billing disputes, or mail that appears lost, direct the user to support@getmailr.com.

# Lead captured outbound delivery

> When a lead is captured on one of your Mailr landing pages, Mailr POSTs
this payload to every subscription registered for `lead.created`. Only
landing-page leads are delivered; CRM-synced leads never are.

**Signature verification.** A subscription that carries a `signing_secret`
receives two headers:

  - `X-Mailr-Timestamp`: unix seconds, as sent.
  - `X-Mailr-Signature`: `sha256=<hex HMAC-SHA256>` computed over the
    string `"<timestamp>.<rawBody>"`, where `rawBody` is the exact bytes of
    the request body.

Verify by recomputing the HMAC over `"<X-Mailr-Timestamp>.<rawBody>"` with
your secret and comparing in constant time, and reject timestamps drifting
more than **300 seconds** from now (replay protection). Subscriptions with
a null secret are delivered without these headers.

**Loop guard.** The payload includes `mailr_lead_id` (equal to `id`). If
your automation later posts this record back to `POST /api/v1/events`,
stamp that value in `record.properties.mailr_lead_id` so Mailr recognises
its own lead and skips campaign matching.




## OpenAPI

````yaml /api-reference/openapi.yaml webhook lead.created
openapi: 3.1.0
info:
  title: Mailr Developer API
  version: 1.0.0
  description: >
    The Mailr Developer API lets a contractor's own CRM or automation stack
    drive

    Mailr directly with a per-tenant bearer key — no vendor polling, no Zapier
    in

    the middle. You push **events** when a job or deal changes, Mailr matches
    them

    against the automations you configured in the app and mails per-recipient

    Street View postcards; you push **won deals** and **leads** for revenue

    attribution; you **subscribe** an endpoint to receive captured leads back

    (HMAC-signed); and you **stage past jobs** for a reactivation campaign.


    ## Authentication


    Every endpoint here authenticates with an organization-scoped API key

    presented as `Authorization: Bearer ak_…`. The key alone identifies the

    tenant — you never pass an `org_id`, connection id, or batch id in the body
    or

    query; anything you could name is derived from the key. Create keys in the

    Mailr app under your workspace name (bottom-left) -> Manage account ->

    API keys (workspace Owner only).


    ## Scopes


    Keys may declare scopes. Policy (v1): if a key declares **any** scopes, it
    must

    include the scope an operation requires; a key that declares **no** scopes
    is

    treated as unrestricted and passes every check. The scopes in use are

    `events:write`, `import:write`, and `webhooks:inbound`. Each operation below

    documents its required scope under `x-required-scope`.


    ## Base URL


    Production is `https://app.getmailr.com`. All paths below are relative to
    it.


    ## Versioning


    The public API is versioned under `/api/v1/*` — every endpoint documented

    here lives under it. The Mailr Zapier app targets `/api/v1/*`; build new

    integrations against the same prefix.


    ## Idempotency


    Write endpoints are idempotent on a caller-supplied key: `dedup_id` on
    events,

    `deal_id`/address on conversions and leads. Imports are **not**
    deduplicated:

    one request is one batch, and duplicate addresses within or across batches
    are

    staged independently.

    Replaying the same request is safe and is reported back to you (e.g.

    `duplicate: true`, `idempotent: true`, or `reason: "duplicate"`).


    ## Auth-path errors (all endpoints)


    Besides each endpoint's own statuses, every authenticated endpoint can

    return two RETRYABLE auth-path errors: `429` `{ "error": "rate_limited" }`

    when the pre-auth per-IP limit (60/min/IP) trips, and `503`

    `{ "error": "auth_unavailable" }` when the auth provider is temporarily

    unreachable (your key was NOT checked). Both carry `Retry-After`. Neither

    means your key is bad — only a `401` does.


    ## Delivery cadence


    There is **no reconciliation sweep**. Mailr does not reach back into your
    CRM

    to pull anything it missed — the caller is the sync. If a push fails or you

    suspect a gap, **replay your events**; idempotency makes replays free.
  contact:
    name: Mailr
    url: https://app.getmailr.com
servers:
  - url: https://app.getmailr.com
    description: Production
security:
  - bearerAuth: []
tags:
  - name: Events
    description: Push CRM/automation events that trigger campaigns (Developer API v1).
  - name: Imports
    description: >-
      Stage a batch of past jobs/customers for a reactivation campaign
      (Developer API v1).
  - name: Leads
    description: Receive captured leads (subscribe) and poll recent leads.
  - name: Attribution
    description: >-
      Report won deals and synced leads so revenue attributes to the campaign
      that mailed the address.
  - name: Customers
    description: Register existing customers for address suppression.
  - name: Account
    description: Identify the key's organization and list its automations.
paths: {}
components:
  securitySchemes:
    bearerAuth:
      type: http
      scheme: bearer
      bearerFormat: ak_
      description: 'Organization-scoped Mailr API key. Header: `Authorization: Bearer ak_…`.'

````