Developers

Snippet, webhooks, and a token.

Integrate the helpdesk with your own systems. Rotate secrets in Settings. OpenAPI lives on the API host at /docs in development only — not on this site.

Widget

See Widget for the snippet. The script is served from the API host at /embed/xupport.js. It talks to that same host. CORS is limited to the origins we configure.

Signed webhooks

Settings: webhook URL and secret. We POST JSON { "type": "…", "data": { } } with headers:

  • X-Xupport-Timestamp — unix seconds
  • X-Xupport-Signature — sha256= HMAC of timestamp + "." + raw body using your secret

Events: conversation.created, conversation.updated, message.created. Send a ping with “Test webhook”. There is no retry queue in this version. Verify the signature before you trust the body.

Public API token

Rotate api_token in Settings. Call GET /v1/conversations with Authorization: Bearer YOUR_TOKEN. The token is scoped to your organisation. Treat it like a password.

What we do not offer in this version

No per-customer SAML. Google sign-in uses one platform OAuth client. No WhatsApp or SMS API. No webhook retry dashboard.

Questions about a workspace you pay for: hello@xupport.io. Or use the chat on this site.

Developer docs — widget, webhooks, API · Xupport