Choose an interface
REST and MCP keys must stay on a trusted server or in the MCP client’s secret configuration. Never place either key in browser-delivered JavaScript. A publishable key is browser-visible, is intended for Web Chat, and is not a general REST credential. The SDK v0.1.44
requestContact option is not supported on untrusted public sites while backend hardening is pending; see Web Chat.
Base URL
Direct REST requests authenticate with the
X-API-Key header. See Authentication for how to choose, obtain, and manage a key.
Quick Start
1. Get your API key
Create and manage REST keys under Settings → API Keys in Nexor. See Authentication for the full steps. REST keys start withnxr_live_ and are intended for server-to-server use.
2. Create a lead
workflow_id identifies an active agent, Nexor creates the lead and enrolls it in that agent. The response includes workflow_run when enrollment succeeds or a warning if the lead was created but enrollment failed.
What you can do
- Create and manage leads. Add leads individually or in bulk, update their information, and store custom metadata.
- Assign agents. Enroll leads into automated AI-powered outreach agents with multi-channel cadences.
- Track conversions. Record business outcomes like reservations and closed sales with custom field metadata.
- Send messages. Send WhatsApp messages (text or template), emails, or trigger AI phone calls to any lead.
Rate Limits
Standard external API traffic is limited to 300 requests per minute per IP address. Requests beyond that return429 Too Many Requests.
MCP keys carry an additional per-key limit of 600 requests per minute. REST keys are not subject to that second limit. For REST keys, only the per-IP limit applies.
Rate-limit responses from the per-IP and MCP per-key limits include Retry-After in seconds. Honor it rather than retrying on a fixed timer. When the MCP per-key limiter runs, it also adds X-RateLimit-Limit, X-RateLimit-Remaining, and X-RateLimit-Reset to the response.
OpenAPI Specification
The OpenAPI specification is available at/openapi.json.
The current specification publishes 259 customer REST operations from a pinned inventory of 307 public-route operations. The other 48 are intentionally omitted because they are internal administration or plumbing, browser transport, compatibility aliases, feature-gated experiments, or operations whose current behavior is not safe or reliable enough to present as a supported contract. Eighteen obsolete or excluded entries from the previous reference set are no longer in navigation.