RelayDocs

API reference

API overview

Relay’s HTTP API is plain JSON over HTTPS, served from Relay. There are three groups of endpoints, and each one needs to know which workspace it is for.

APIWho calls itWorkspaceVisitor / authCross-origin
Feedback APIYour frontend or backendkeyx-visitor-idYes: open CORS
Widget APIThe support widgetkeyx-visitor-idNo: same origin only
Owner APIThe inboxYour sessionSession cookieNo

Base URL#

All paths are relative to the Relay address:

https://support.notaislop.xyz/api/...

Which workspace#

One Relay serves many businesses, so every request names the workspace it is for. The public APIs (feedback, widget) take your workspace’s public key, as a key query parameter or an x-relay-key header:

GET https://support.notaislop.xyz/api/feedback?key=wk_XXXXXXXXXXXXXXXXXXXXXXXX

The key is shown under Inbox → Settings → Install. It isn’t a secret: it sits in your page source like any embed, and it only lets someone talk to your support team or your public board. The owner API uses your signed-in session instead.

Visitor identity#

Public endpoints identify the person acting with an x-visitor-id header: 12 to 64 characters of letters, digits, _ or -. There are no API keys. See choosing a visitor id.

Requests and responses#

  • Send JSON bodies with content-type: application/json.
  • Timestamps are ISO 8601 strings in UTC, e.g. 2026-09-12T10:01:00.000Z.
  • Text fields are trimmed and cut to their maximum length.
  • Lists return at most 200 items.

Errors#

Errors return a JSON body with a readable message, safe to show to users:

json
{ "error": "Title is required" }
StatusMeaning
400Validation failed (empty or invalid field), or no workspace key was sent.
401Missing or malformed x-visitor-id, or not signed in (owner endpoints).
402The workspace isn’t active: its subscription has lapsed. The body’s code says why.
403You’re signed in but aren’t allowed to do this (for example an agent trying to manage billing).
404The resource doesn’t exist or isn’t yours, or the workspace key is unknown.
429Too many requests from one IP address. Wait and try again.

Realtime#

The widget and inbox receive live updates over Server-Sent Events (/api/widget/stream, /api/admin/stream). Events only say what changed; clients then refetch.

Stability#

The Feedback API is designed for you to build on. Its fields and behavior will only change in a backwards-compatible way. The widget and owner APIs exist to serve Relay’s own interfaces and may change between versions. A keyed public REST API and webhooks are on the roadmap.