Relay’s HTTP API is plain JSON over HTTPS, served from Relay. There are three groups of endpoints, and each one needs to know which workspace it is for.
Base URL#
All paths are relative to the Relay address:
https://support.notaislop.xyz/api/...Which workspace#
One Relay serves many businesses, so every request names the workspace it is for. The public APIs (feedback, widget) take your workspace’s public key, as a key query parameter or an x-relay-key header:
GET https://support.notaislop.xyz/api/feedback?key=wk_XXXXXXXXXXXXXXXXXXXXXXXXThe key is shown under Inbox → Settings → Install. It isn’t a secret: it sits in your page source like any embed, and it only lets someone talk to your support team or your public board. The owner API uses your signed-in session instead.
Visitor identity#
Public endpoints identify the person acting with an x-visitor-id header: 12 to 64 characters of letters, digits, _ or -. There are no API keys. See choosing a visitor id.
Requests and responses#
- Send JSON bodies with
content-type: application/json. - Timestamps are ISO 8601 strings in UTC, e.g.
2026-09-12T10:01:00.000Z. - Text fields are trimmed and cut to their maximum length.
- Lists return at most 200 items.
Errors#
Errors return a JSON body with a readable message, safe to show to users:
{ "error": "Title is required" }Realtime#
The widget and inbox receive live updates over Server-Sent Events (/api/widget/stream, /api/admin/stream). Events only say what changed; clients then refetch.
Stability#
The Feedback API is designed for you to build on. Its fields and behavior will only change in a backwards-compatible way. The widget and owner APIs exist to serve Relay’s own interfaces and may change between versions. A keyed public REST API and webhooks are on the roadmap.