curl --request GET \
--url https://{subdomain}.conveyour.com/api/messages \
--header 'x-conveyour-token: <api-key>'const options = {method: 'GET', headers: {'x-conveyour-token': '<api-key>'}};
fetch('https://{subdomain}.conveyour.com/api/messages', options)
.then(res => res.json())
.then(res => console.log(res))
.catch(err => console.error(err));const options = {method: 'GET', headers: {'x-conveyour-token': '<api-key>'}};
fetch('https://{subdomain}.conveyour.com/api/messages', options)
.then(res => res.json())
.then(res => console.log(res))
.catch(err => console.error(err));import requests
url = "https://{subdomain}.conveyour.com/api/messages"
headers = {"x-conveyour-token": "<api-key>"}
response = requests.get(url, headers=headers)
print(response.text)<?php
$curl = curl_init();
curl_setopt_array($curl, [
CURLOPT_URL => "https://{subdomain}.conveyour.com/api/messages",
CURLOPT_RETURNTRANSFER => true,
CURLOPT_ENCODING => "",
CURLOPT_MAXREDIRS => 10,
CURLOPT_TIMEOUT => 30,
CURLOPT_HTTP_VERSION => CURL_HTTP_VERSION_1_1,
CURLOPT_CUSTOMREQUEST => "GET",
CURLOPT_HTTPHEADER => [
"x-conveyour-token: <api-key>"
],
]);
$response = curl_exec($curl);
$err = curl_error($curl);
curl_close($curl);
if ($err) {
echo "cURL Error #:" . $err;
} else {
echo $response;
}{
"status": "ok",
"message": "success",
"data": [
{
"id": "64a1b2c3d4e5f6a7b8c9d0e1",
"class": "sms",
"type": "contact",
"type_id": "64a1b2c3d4e5f6a7b8c9d0e2",
"body": "Hi Jane, your session is confirmed.",
"created_at": 1718438400
}
]
}{
"status": "failed",
"message": "Lacking necessary permission add_contacts",
"data": {
"permission": "add_contacts"
}
}List messages
Returns outbound messages for the org (excludes thread replies — only original sent messages).
Result cap: at most 100 messages, sorted newest first (created_at descending). This endpoint does not paginate, so there is no way to reach older messages beyond the first 100.
Truncated body: body comes back shortened on this endpoint. Fetch a message by ID for the full text.
Silently omitted records: a message whose related bookmark, trigger or campaign has been deleted resolves its name to the bare type string and is filtered out of the response.
Conversations vs messages. Most day-to-day work happens against conversations — GET /api/messages/conversations returns the threaded view, while this endpoint lists original outbound sends only and excludes thread replies.
curl --request GET \
--url https://{subdomain}.conveyour.com/api/messages \
--header 'x-conveyour-token: <api-key>'const options = {method: 'GET', headers: {'x-conveyour-token': '<api-key>'}};
fetch('https://{subdomain}.conveyour.com/api/messages', options)
.then(res => res.json())
.then(res => console.log(res))
.catch(err => console.error(err));const options = {method: 'GET', headers: {'x-conveyour-token': '<api-key>'}};
fetch('https://{subdomain}.conveyour.com/api/messages', options)
.then(res => res.json())
.then(res => console.log(res))
.catch(err => console.error(err));import requests
url = "https://{subdomain}.conveyour.com/api/messages"
headers = {"x-conveyour-token": "<api-key>"}
response = requests.get(url, headers=headers)
print(response.text)<?php
$curl = curl_init();
curl_setopt_array($curl, [
CURLOPT_URL => "https://{subdomain}.conveyour.com/api/messages",
CURLOPT_RETURNTRANSFER => true,
CURLOPT_ENCODING => "",
CURLOPT_MAXREDIRS => 10,
CURLOPT_TIMEOUT => 30,
CURLOPT_HTTP_VERSION => CURL_HTTP_VERSION_1_1,
CURLOPT_CUSTOMREQUEST => "GET",
CURLOPT_HTTPHEADER => [
"x-conveyour-token: <api-key>"
],
]);
$response = curl_exec($curl);
$err = curl_error($curl);
curl_close($curl);
if ($err) {
echo "cURL Error #:" . $err;
} else {
echo $response;
}{
"status": "ok",
"message": "success",
"data": [
{
"id": "64a1b2c3d4e5f6a7b8c9d0e1",
"class": "sms",
"type": "contact",
"type_id": "64a1b2c3d4e5f6a7b8c9d0e2",
"body": "Hi Jane, your session is confirmed.",
"created_at": 1718438400
}
]
}{
"status": "failed",
"message": "Lacking necessary permission add_contacts",
"data": {
"permission": "add_contacts"
}
}Authorizations
Your API key token. Contacts endpoints require a Server-only — Full API key — see Authentication.
Query Parameters
Filter by message type(s). Valid values: contact, bookmark, trigger, campaign, trigger_lesson, trigger_wait. Invalid values are dropped; if nothing valid remains the filter falls back to all types rather than erroring.
contact, bookmark, trigger, campaign, trigger_lesson, trigger_wait Filter by creator type(s). Valid values: user, system, team, automatic. Omit it and all four are used. But if you pass a value and none of it is valid, the filter silently narrows to user only — the opposite of how types behaves. No error is returned either way.
user, system, team, automatic Team scope for the request, as one or more team ObjectIds. The brackets are required: PHP keeps only the last value for a repeated plain key, so teams=A&teams=B silently resolves to B alone. On requests with a JSON body you may send teams (no brackets) in the body instead.
Values that are not valid ObjectIds are silently ignored — a mistyped team ID behaves as if no team was sent. See the teams section of the API conventions guide.