RacLink Docs
Open app
API

The RacLink API

The RacLink API lets your own code, scripts and other platforms do the work you would otherwise do by hand in the app: CRM records, invoices, files, mail, dashboards, connected apps, agents, the AI workforce and Hydra. It is a plain HTTPS and JSON API, so anything that can make a web request can use it.

The one idea behind it

An API key acts as the person who created it. Every single call re-checks that person's permissions live, so a key can never do more than its owner can. Change someone's permissions and their keys change with them immediately; remove them from the workspace and their keys stop working at once. There is nothing to re-issue and nothing to remember to clean up.

A key is you, narrowed
A key starts with your permissions and can only ever be narrowed from there. Nothing can widen one — not another endpoint, not an admin, not asking an AI to do the work for it.

What you can do with it

  • Read and write CRM records: contacts, companies, customers and deals.
  • Raise, update, send and track invoices, and manage products and expenses.
  • Upload, organise, read and download files and folders in AI Drive.
  • Send email, and draft it with AI first.
  • Read and build dashboards.
  • Generate text with the platform model or any AI model your workspace has linked.
  • Run agents, hand work to the AI workforce, and talk to Hydra.
  • Start lead generation, campaigns, workflows and AI phone calls.
  • Use the apps and APIs you have already connected under Integrations.
  • See your workspace, your team, your credits and your own API usage.

The three reference pages at the end of this section list every endpoint, what it does, and the permission it needs.

How a call works

  1. 1
    You send a request
    An HTTPS request with your key in the Authorization header, and a JSON body if you are creating or changing something.
  2. 2
    We work out who you are
    The key is matched to the member who owns it, and their membership of this workspace is confirmed against the live sign-in system rather than a stored copy.
  3. 3
    We work out what you may do
    Their permissions right now, then the key's own access mode, then any admin or plan rule for that endpoint. All of them have to agree before anything runs.
  4. 4
    We check the budget
    Your rate limit, your monthly call quota, and — for anything that uses AI — your credit balance.
  5. 5
    The work happens
    The endpoint acts inside your workspace only and answers with JSON. Anything long-running answers immediately with an id you can poll while it finishes.

Worth knowing before you start

Base URL
https://app.raclink.si/api/v1 — the version lives in the path, so /v1 keeps working even after a v2 arrives.
Server-side only
The API deliberately sends no browser CORS headers. Call it from your own server or scripts, never from front-end code, where a key would be visible to anyone who opens the page.
JSON in, JSON out
Requests with a body send Content-Type: application/json. Every response is a JSON object and carries a request_id you can quote to support.
New fields can appear
New endpoints and new optional fields ship at any time. Parse leniently and ignore anything you do not recognise; changes that would break you go in a new version path instead.
Everything is scoped to one workspace
A key belongs to a single workspace and can never see another one, even if its owner is a member of several.

What the API will never do

Some things are deliberately impossible through the API, whatever permissions a key holds. These are decisions, not gaps.

  • Create or manage API keys. Keys are only ever made by a signed-in person in Settings, so a leaked key cannot breed more keys.
  • Change permissions, roles, or who is on the team.
  • Approve or decline anything that is waiting for a human decision.
  • Change your plan, buy credits, or touch billing in any way.
  • Read or change another member's private chats, runs, mailbox or notifications.
  • Pick its own AI model price, credit rate or quota — every one of those is decided on our side.
Where to go next
Create a key, then make your first call. Settings → API also has a terminal that writes a ready-to-run example for any endpoint in eight languages, with your parameters already filled in.