> ## Documentation Index
> Fetch the complete documentation index at: https://docs.getmailr.com/llms.txt
> Use this file to discover all available pages before exploring further.

> ## Agent Instructions
> Mailr is a direct-mail marketing platform for US home-services contractors. Each postcard is personalized with an AI-enhanced image of the recipient's own home and a unique QR code that leads to a personalized landing page. Campaigns can target a neighborhood the customer draws on a map, the homes around past jobs they upload or import, or fire automatically from their CRM. Mailr does not mail an uploaded recipient list. When answering questions, prefer the exact steps and UI labels from these docs, and direct users to app.getmailr.com to sign in. For anything involving account-specific data, billing disputes, or mail that appears lost, direct the user to support@getmailr.com.

# Subscribe an endpoint to receive captured leads

> Register a public HTTPS URL to receive `lead.created` deliveries (a lead
captured on one of your Mailr landing pages). Only landing-page leads fan
out here — CRM-synced leads (see `POST /api/v1/tracking/lead`) never do, to
avoid an echo loop.

The response returns a `signing_secret` **exactly once, at creation**.
Store it: every delivery to a secret-bearing subscription is HMAC-signed
(see the `lead.created` webhook below). Re-subscribing the same URL is
idempotent — it returns the existing row's id with
`signing_secret: null` (secrets are never re-disclosed and never
silently rotated, so a re-subscribe can't break a receiver mid-flight
and a compromised API key can't recover live secrets). Lost the secret?
`POST /api/v1/webhooks/rotate` mints a new one and returns it once. A
subscription created before signing shipped is delivered unsigned;
delete and re-subscribe (or rotate) to upgrade it.

The URL is SSRF-guarded at registration (public https only; hostname must
resolve to public addresses) and again at delivery time.




## OpenAPI

````yaml /api-reference/openapi.yaml post /api/v1/webhooks/subscribe
openapi: 3.1.0
info:
  title: Mailr Developer API
  version: 1.0.0
  description: >
    The Mailr Developer API lets a contractor's own CRM or automation stack
    drive

    Mailr directly with a per-tenant bearer key — no vendor polling, no Zapier
    in

    the middle. You push **events** when a job or deal changes, Mailr matches
    them

    against the automations you configured in the app and mails per-recipient

    Street View postcards; you push **won deals** and **leads** for revenue

    attribution; you **subscribe** an endpoint to receive captured leads back

    (HMAC-signed); and you **stage past jobs** for a reactivation campaign.


    ## Authentication


    Every endpoint here authenticates with an organization-scoped API key

    presented as `Authorization: Bearer ak_…`. The key alone identifies the

    tenant — you never pass an `org_id`, connection id, or batch id in the body
    or

    query; anything you could name is derived from the key. Create keys in the

    Mailr app under your workspace name (bottom-left) -> Manage account ->

    API keys (workspace Owner only).


    ## Scopes


    Keys may declare scopes. Policy (v1): if a key declares **any** scopes, it
    must

    include the scope an operation requires; a key that declares **no** scopes
    is

    treated as unrestricted and passes every check. The scopes in use are

    `events:write`, `import:write`, and `webhooks:inbound`. Each operation below

    documents its required scope under `x-required-scope`.


    ## Base URL


    Production is `https://app.getmailr.com`. All paths below are relative to
    it.


    ## Versioning


    The public API is versioned under `/api/v1/*` — every endpoint documented

    here lives under it. The Mailr Zapier app targets `/api/v1/*`; build new

    integrations against the same prefix.


    ## Idempotency


    Write endpoints are idempotent on a caller-supplied key: `dedup_id` on
    events,

    `deal_id`/address on conversions and leads. Imports are **not**
    deduplicated:

    one request is one batch, and duplicate addresses within or across batches
    are

    staged independently.

    Replaying the same request is safe and is reported back to you (e.g.

    `duplicate: true`, `idempotent: true`, or `reason: "duplicate"`).


    ## Auth-path errors (all endpoints)


    Besides each endpoint's own statuses, every authenticated endpoint can

    return two RETRYABLE auth-path errors: `429` `{ "error": "rate_limited" }`

    when the pre-auth per-IP limit (60/min/IP) trips, and `503`

    `{ "error": "auth_unavailable" }` when the auth provider is temporarily

    unreachable (your key was NOT checked). Both carry `Retry-After`. Neither

    means your key is bad — only a `401` does.


    ## Delivery cadence


    There is **no reconciliation sweep**. Mailr does not reach back into your
    CRM

    to pull anything it missed — the caller is the sync. If a push fails or you

    suspect a gap, **replay your events**; idempotency makes replays free.
  contact:
    name: Mailr
    url: https://app.getmailr.com
servers:
  - url: https://app.getmailr.com
    description: Production
security:
  - bearerAuth: []
tags:
  - name: Events
    description: Push CRM/automation events that trigger campaigns (Developer API v1).
  - name: Imports
    description: >-
      Stage a batch of past jobs/customers for a reactivation campaign
      (Developer API v1).
  - name: Leads
    description: Receive captured leads (subscribe) and poll recent leads.
  - name: Attribution
    description: >-
      Report won deals and synced leads so revenue attributes to the campaign
      that mailed the address.
  - name: Customers
    description: Register existing customers for address suppression.
  - name: Account
    description: Identify the key's organization and list its automations.
paths:
  /api/v1/webhooks/subscribe:
    post:
      tags:
        - Leads
      summary: Subscribe an endpoint to receive captured leads
      description: >
        Register a public HTTPS URL to receive `lead.created` deliveries (a lead

        captured on one of your Mailr landing pages). Only landing-page leads
        fan

        out here — CRM-synced leads (see `POST /api/v1/tracking/lead`) never do,
        to

        avoid an echo loop.


        The response returns a `signing_secret` **exactly once, at creation**.

        Store it: every delivery to a secret-bearing subscription is HMAC-signed

        (see the `lead.created` webhook below). Re-subscribing the same URL is

        idempotent — it returns the existing row's id with

        `signing_secret: null` (secrets are never re-disclosed and never

        silently rotated, so a re-subscribe can't break a receiver mid-flight

        and a compromised API key can't recover live secrets). Lost the secret?

        `POST /api/v1/webhooks/rotate` mints a new one and returns it once. A

        subscription created before signing shipped is delivered unsigned;

        delete and re-subscribe (or rotate) to upgrade it.


        The URL is SSRF-guarded at registration (public https only; hostname
        must

        resolve to public addresses) and again at delivery time.
      operationId: subscribeWebhook
      requestBody:
        required: true
        content:
          application/json:
            schema:
              $ref: '#/components/schemas/SubscribeRequest'
            example:
              target_url: https://hooks.example.com/mailr/leads
              event: lead.created
      responses:
        '200':
          description: >-
            Subscribed (or already subscribed). Note this is 200, not 201, on
            both create and idempotent re-subscribe.
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/SubscribeResult'
              example:
                id: b7c8d9e0-0000-0000-0000-000000000010
                signing_secret: >-
                  9f8e7d6c5b4a39281706f5e4d3c2b1a09f8e7d6c5b4a39281706f5e4d3c2b1a0
        '400':
          description: Missing/invalid `target_url`, unsupported event, or invalid JSON.
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/Error'
              examples:
                notPublic:
                  value:
                    error: target_url must be a public https URL
                unsupported:
                  value:
                    error: 'Unsupported event: deal.won'
        '401':
          description: Unauthorized.
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/Error'
              example:
                error: Unauthorized
        '403':
          description: Key resolves to no org or lacks `webhooks:inbound`.
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/Error'
              example:
                error: Unauthorized
        '500':
          description: Failed to subscribe.
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/Error'
              example:
                error: Failed to subscribe
components:
  schemas:
    SubscribeRequest:
      type: object
      required:
        - target_url
      properties:
        target_url:
          type: string
          format: uri
          description: Public https URL to deliver to. SSRF-guarded.
        event:
          type: string
          enum:
            - lead.created
          default: lead.created
    SubscribeResult:
      type: object
      required:
        - id
        - signing_secret
      properties:
        id:
          type: string
          format: uuid
        signing_secret:
          type:
            - string
            - 'null'
          description: >-
            Hex secret for HMAC verification. Present only when the subscription
            was just created (or via /api/v1/webhooks/rotate) — an idempotent
            re-subscribe returns null, as does a pre-signing subscription
            (delivered unsigned).
    Error:
      type: object
      description: >
        Error body. `error` is a stable machine code; `detail` (when present) is
        a

        human-readable explanation naming the offending field. Note two families

        of code style coexist across the API: snake_case machine codes on the v1

        and rate-limited endpoints (`invalid_payload`, `rate_limited`,

        `automations_disabled`) and human sentences on the legacy endpoints

        (`Unauthorized`, `No address found in payload`). Both are returned in
        the

        `error` field.
      required:
        - error
      properties:
        error:
          type: string
          example: invalid_payload
        detail:
          type: string
          example: event_type is required
  securitySchemes:
    bearerAuth:
      type: http
      scheme: bearer
      bearerFormat: ak_
      description: 'Organization-scoped Mailr API key. Header: `Authorization: Bearer ak_…`.'

````