Changelog

Public API v1 (current)

  • REST under /public/v1 — credits, accounts, activity, insights overview, campaigns (list/get, start/pause, lookalike), leads (single + batch add/update/delete), send, LinkedIn lookup/search
  • Outbound webhooks (4 events); manage subscriptions in /api-mcp
  • MCP tools 1:1 with REST (https://mcp.scaliq.ai)
  • MCP URLs expose a no-key short overview at GET /, /.well-known/mcp.json, and /llms.txt (tool names + summaries only; full schemas via MCP tools/list)

Recent additions (non-breaking)

  • Insights: GET /activity (recent outreach events), GET /insights/overview (sampled campaign ranking + last-reply highlights). Lead list/detail add ISO repliedAt / lastInboundMessageAt / taggedAt and optional sort. MCP tools get_recent_activity / get_insights_overview.
  • Lead batch ops: POST …/leads/batch-update (tag/exclude, max 100, 0 credits, 6/min), POST …/leads/batch-delete (permanent delete, max 100, 0 credits, no refund, 10/min), GET …/leads?excluded=true. MCP tools update_leads_batch / delete_leads_batch (destructiveHint + idempotentHint on delete).
  • POST /campaigns/:campaignId/leads/batch — up to 100 URLs per request; 1 credit per successful create; partial 200 with per-item results + summary; MCP add_leads_batch; 10 requests / minute. Prefer batch for CRM / n8n bulk push instead of parallel single-lead calls.
  • POST /campaigns/lookalike — async Lookalike campaign create/extend (Lookalike allowance). Optional countries (ISO alpha-2) person location filter. MCP tool create_lookalike_campaign. GET /credits adds lookalikeCredits / lookalikeTopUpCredits.
  • Signed webhook deliveries now also include a neutral X-Webhook-Signature header (same value as X-ScaliQ-Signature). Prefer it for new integrations; the ScaliQ-named header keeps working.
  • lead.tagged (and other outbound events) fill data.accountId from the lead’s LinkedIn account id, then fall back to the matching inbox chat’s accountId when the lead field is missing.
  • Outbound webhook signing uses a static shared secret: when you set a signing secret, ScaliQ sends X-ScaliQ-Signature: <that exact string> (works with n8n Header Auth). Previously this was an HMAC sha256= digest.
  • GET /accounts accepts limit / cursor and returns nextCursor. Existing callers that read accounts keep working; only workspaces with more than 50 accounts need to page.
  • 413 for request bodies over 128 KiB.
  • On POST .../leads, POST .../leads/batch, POST .../leads/batch-update, POST .../leads/batch-delete, POST /inbox/messages, and POST /campaigns/lookalike, an Idempotency-Key that we cannot record now returns 503 with nothing performed, instead of running the request unprotected.

Future breaking changes will be listed here.