Developers
Snippet, webhooks, and a token.
Integrate the helpdesk with your own systems. Rotate secrets in Settings. OpenAPI lives on the API host at /docs in development only — not on this site.
Widget
See Widget for the snippet. The script is served from the API host at /embed/xupport.js. It talks to that same host. CORS is limited to the origins we configure.
Signed webhooks
Settings: webhook URL and secret. We POST JSON { "type": "…", "data": { } } with headers:
X-Xupport-Timestamp— unix secondsX-Xupport-Signature—sha256=HMAC oftimestamp + "." + raw bodyusing your secret
Events: conversation.created, conversation.updated, message.created. Send a ping with “Test webhook”. There is no retry queue in this version. Verify the signature before you trust the body.
Public API token
Rotate api_token in Settings. Call GET /v1/conversations with Authorization: Bearer YOUR_TOKEN. The token is scoped to your organisation. Treat it like a password.
What we do not offer in this version
No per-customer SAML. Google sign-in uses one platform OAuth client. No WhatsApp or SMS API. No webhook retry dashboard.
Questions about a workspace you pay for: hello@xupport.io. Or use the chat on this site.