Base URL
Authentication
Referer headers.
The two exceptions
POST /v1/users and POST /v1/answer take the workspace secret key
(sk_…) instead. They are machine paths that run in your backend on a signup
hook or a schedule, and tying a production pipeline to one employee’s token
would break the day they leave.
/v1 is not uniform. Every operation states its credential and its
required role. Check the operation, not the namespace.
See Credentials for the full model and
Roles for what each role reaches.
What the API covers
24 paths, 32 operations.
Start with API conventions — the envelope, pagination and
error shape are the same everywhere.
What you cannot write through the API
Some data is collected by Peeve and is read-only to you. There is no endpoint to submit it, deliberately.What is not in the API
The widget
A script tag, driven with
identify and setContext. Its own HTTP calls are
internal and are not a supported integration point.MCP
JSON-RPC, not REST. Takes an API token; the role governs what is reachable.
Conventions
- Request and response bodies are JSON.
- Timestamps are ISO 8601.
- Placeholder credentials here (
pv_ut_xxx,sk_live_xxx) are not real.