Documentation
REST API v1
The REST API gives scripts and integrations the same scoped access as the connector. It accepts only API tokens; OAuth tokens work only on the MCP endpoint.
Basics
- Base URL:
https://app.leitvik.com/api/v1 - Header:
Authorization: Bearer qre_…. Requests and responses are JSON. - Rate limit: the token's own limit per minute (60 by default, 1 to 600), shared with the connector. Over it the answer is
429withRetry-After. - Lists default to 50 items and cap at 100, with
limitandoffset; responses includehasMore. - Dates use the workspace timezone.
First request
curl -s "https://app.leitvik.com/api/v1/context" \
-H "authorization: Bearer $LEITVIK_TOKEN"Idempotent writes
Record writes accept a requestId (UUID) in the body or an Idempotency-Key header. For 24 hours a repeat with the same key and content returns the first result without writing again; the same key with different content is 409. Task, opportunity and capture writes require their own requestId.
Versions
Tasks and opportunities carry a version. Send the current one with every change; a stale version is 409, so read again and decide again.
Endpoints
| Method | Path | Scope |
|---|---|---|
GET | /api/v1/context | Any scope |
GET | /api/v1/companies?q=&limit=&offset= | companies:read |
GET | /api/v1/companies/{id} | companies:read |
PUT | /api/v1/companies | companies:write |
GET | /api/v1/companies/{id}/brief | companies:readleads:readtouches:readsignals:read |
GET | /api/v1/contacts?companyId= | contacts:read |
PUT | /api/v1/contacts | contacts:write |
GET | /api/v1/leads?q=&status= | leads:read |
PATCH | /api/v1/leads/{id} | leads:write |
GET | /api/v1/touches?companyId= | touches:read |
POST | /api/v1/touches | touches:write |
GET | /api/v1/signals?companyId= | signals:read |
POST | /api/v1/signals | signals:write |
GET | /api/v1/dossiers?companyId= | dossiers:read |
PUT | /api/v1/dossiers | dossiers:write |
GET | /api/v1/today?limit=&offset= | leads:read |
GET | /api/v1/tasks?status=&due=&owner=&companyId= | tasks:read |
POST | /api/v1/tasks | tasks:write |
PATCH | /api/v1/tasks/{id} | tasks:write |
GET | /api/v1/opportunities?companyId=&stage= | opportunities:read |
POST | /api/v1/opportunities | opportunities:write |
PATCH | /api/v1/opportunities/{id} | opportunities:write |
POST | /api/v1/captures | captures:write |
POST | /api/v1/captures/{id}/apply | captures:write |
POST | /api/v1/captures/{id}/undo | captures:write |
Errors
Error bodies are { "error": code }. They never include stack traces, SQL or your input.
| Status | Code | Meaning |
|---|---|---|
| 400 | validation | Invalid input. |
| 401 | unauthorized | Missing, expired or revoked token, or missing scope. |
| 403 | forbidden | The token cannot do it. |
| 404 | not_found | Not in this workspace. |
| 409 | conflict | Stale version, invalid transition, or reused key with different content. |
| 413 | too_large | Body over the limit. |
| 429 | rate_limited | Too many requests; wait Retry-After seconds. |