REST API

The routes the app calls, how they sign in, how they are laid out, and why they are not a supported public API.

The app talks to the server over JSON routes under one base address. This section documents them so you can see what the app does, but it is not a promise: they are private, they can change, and a connector key does not work on them.

Not a supported public API

Use the MCP connector if you need something that stays put. If you need these calls inside your own product, the Stack page has an API line marked "On request". Ask through hello@adaptleads.co.uk and describe what you want to build.

Base address and format

  • Base: https://app.adaptleads.co.uk/api. Every route here starts /market, so a full address is https://app.adaptleads.co.uk/api/market/catalog/search.
  • Requests and responses are JSON, except the CSV export, the audio from voice/speak, and the extension download.
  • Times are ISO 8601. Ids are strings. A record id looks like mkt_....
  • Errors are described in Errors and what they mean.

Signing in

Every route except sign-in itself needs Authorization: Bearer <sign-in token>.

POST /market/auth/login
Content-Type: application/json

{"email": "jess@oakfield-it.example", "password": "a long sample password"}
{
  "token": "eyJ...",
  "account": {
    "id": "6650f0c2a1b2c3d4e5f60718",
    "email": "jess@oakfield-it.example",
    "company_name": "Oakfield IT",
    "plan": "growth",
    "export_allowance": 15000,
    "exports_used": 3184,
    "exports_remaining": 11816,
    "credit_balance": 25
  }
}

The token lasts 30 days and carries your account and your current organisation. Sign-in may be refused with 403 if the address is not on the approved list. POST /market/auth/google takes a Google credential instead, and GET /market/auth/me returns the account and the organisation for a token. A key (adl_...) is not accepted here.

The organisation

Your token carries the organisation you are acting in. Nothing in the path, query or body can choose a different one. To switch, POST /market/orgs/switch returns a fresh token. Lists, campaigns and the CRM belong to the organisation, and a person who is not a member gets a refusal.

How the routes are laid out

Area Routes begin Guide
Sign-in /market/auth This page
Search and records /market/catalog, /market/leads/{id}/reveal, /market/reveals Search the book, Read a record and reveal contact details
Lists and saved searches /market/account/lists, /market/account/searches Lists and saved searches
Exports /market/exports Export a list to CSV
Campaigns and sequences /market/campaigns, /market/sequences LinkedIn campaigns and sequences
LinkedIn /market/linkedin, /market/activity LinkedIn matching and activity
Account and workspace /market/account, /market/orgs, /market/billing Account, organisation and workspace routes
Chrome extension /market/extension Chrome extension routes
Voice /market/voice Voice routes for speak and transcribe
Ask Adapt and skills /market/ask, /market/skills Run a skill

These routes are the app's own and can change without notice, so there is no public route list. Ask for the connector if you need a supported way in: see What the MCP connector is for.

Rules that apply everywhere

  • Nothing is deleted. Routes that look like DELETE archive instead. A deleted list or campaign is hidden, keeps its data, and can be brought back.
  • Contact details are masked until a record is revealed. Search never returns an email or a phone number.
  • Sign-in decides what you see. The same call from two accounts returns two different answers.
  • Pagination and filters follow Pagination and filters.