A REST API for lists, subscribers, campaigns and automations, and signed webhooks that tell your app what happened the moment it happens. One token, JSON in and out.
REST API and webhooks come with the Pro, Business and Enterprise plans.
https://app.mailcraft.eu/api/v1Authorization: Bearer <token>curl -X POST https://app.mailcraft.eu/api/v1/subscribers \ -H "Authorization: Bearer YOUR_API_TOKEN" \ -H "Accept: application/json" \ -d list_uid=YOUR_LIST_UID \ -d EMAIL=jane@example.com \ -d FIRST_NAME=Jane \ -d tag=shop,newsletter
If the list uses double opt-in, the subscriber gets the confirmation email first.
The full reference with every parameter is in the panel - log in and open the API documentation.
Add an HTTPS address in the panel and MailCraft sends a JSON POST for every event on your account: all lists, campaigns and automations, usually within a minute.
subscriber.subscribedsubscriber.unsubscribedemail.openedemail.clickedemail.bouncedemail.complained{
"id": "01k6c3v9m2x8q4r7t5y1w0z3ab",
"event": "email.clicked",
"occurred_at": "2026-09-30T10:15:02+00:00",
"data": {
"subscriber": {"email": "jane@example.com", "status": "subscribed"},
"list": {"uid": "6a14...", "name": "Newsletter"},
"source": {"type": "campaign", "name": "September", "subject": "News"},
"url": "https://your-shop.com/sale"
}
}
$body = file_get_contents('php://input');
parse_str(str_replace(',', '&', $_SERVER['HTTP_X_MAILCRAFT_SIGNATURE'] ?? ''), $sig);
$expected = hash_hmac('sha256', $sig['t'] . '.' . $body, getenv('MAILCRAFT_WEBHOOK_SECRET'));
if (!hash_equals($expected, $sig['v1'] ?? '') || abs(time() - (int) $sig['t']) > 300) {
http_response_code(400);
exit;
}
$event = json_decode($body, true); // $event['event'], $event['data']
http_response_code(200);
Integrations that switch themselves on and off can add their own webhook address when a user connects and remove it when they disconnect. Same token, same rules as in the panel: up to 5 endpoints, HTTPS only.
GET /api/v1/webhooksPOST /api/v1/webhooksGET /api/v1/webhooks/{uid}DELETE /api/v1/webhooks/{uid}GET /api/v1/webhooks/eventsGET /api/v1/webhooks/samples?event=...curl -X POST https://app.mailcraft.eu/api/v1/webhooks \
-H "Authorization: Bearer YOUR_API_TOKEN" \
-H "Accept: application/json" \
-H "Content-Type: application/json" \
-d '{"url": "https://your-app.com/mailcraft", "events": ["subscriber.subscribed", "email.bounced"]}'
# 201 -> {"data": {"uid": "01k6...", "events": [...], "secret": "whsec_..."}}
Tell us what you are connecting - the people who wrote the API answer the email.