API Reference

Use the OpenAPI schema for generated clients and the endpoint map below for the core Warm.Deals resources used by production integrations.

Base URL

Production API requests use the same HTTPS origin as the application.

https://warm.deals/api/v1

Authentication

Public integrations authenticate with scoped API keys.

X-API-Key: lf_your_key_here
  • A key works in the one workspace it was created in and can do only what its scopes allow: company, campaign, sales, analytics, settings, account — :read / :write, plus company:export, campaign:launch and parsing:run. A Full-access key carries *.
  • Launching a campaign, dialer calls and approving AI SDR drafts need campaign:launch. Other calls can reach real people too: enrolling leads into a sequence needs only campaign:write, and replying to an inbox thread sends the e-mail with company:write — grant those scopes accordingly. Applying a copilot action needs a Full-access key.
  • Switching or listing workspaces, browser push, calendar connections and personal data export happen in the app only — keys get 403 there.
  • GET /api/v1/meta/whoami shows which workspace and scopes a key has.
Loading the live schema…

Schema-first clients

Generate typed clients from /api/v1/meta/openapi.json, or use the maintained SDK patterns documented on the SDK page. The schema is served to authenticated callers only — send your key with the request:

curl -H "X-API-Key: lf_your_key_here" https://warm.deals/api/v1/meta/openapi.json