Xoolink public API v1 · beta
Connect a server, a cloud function or your automation tool to your Xoolink organization's public data.
Read-only. Messages, quotes, pacts, confidential needs and internal data are never exposed. Never put a key in browser or mobile code.
API v1 serves the public side: open needs, public events, and your organization's page. Everything that lives inside a pack stays inside.
1. Create a key
In Xoolink: organization page → Admin dashboard → Public API · beta. Choose the permissions and the expiry, then copy the key — it is shown only once.
2. Authenticate
Authorization: Bearer xool_live_...
3. Read the resources
organization:readPublic page of the organization tied to the key.
opportunities:readRecent public opportunities, with cursor pagination.
opportunities:readCurrent state of one opportunity. Returns 404 if it is no longer public.
events:readPublic events, with cursor pagination.
events:readCurrent state of one event. Returns 404 if it is no longer public.
curl https://xoolink.com/api/v1/organization \
-H "Authorization: Bearer $XOOLINK_API_KEY"
curl "https://xoolink.com/api/v1/opportunities?limit=20" \
-H "Authorization: Bearer $XOOLINK_API_KEY"
curl "https://xoolink.com/api/v1/opportunities/req-123" \
-H "Authorization: Bearer $XOOLINK_API_KEY"
curl "https://xoolink.com/api/v1/events?limit=20" \
-H "Authorization: Bearer $XOOLINK_API_KEY"
curl "https://xoolink.com/api/v1/events/event-123" \
-H "Authorization: Bearer $XOOLINK_API_KEY"
What is never exposed
These objects have no endpoint in the API, today or in any other form: they are readable only by members of the pack or organization concerned.
- Revenue split — frozen shares, amounts, percentages.
- Payments in and out, including their confirmations.
- Milestones and documents of a pack, and its private thread.
- Positions and prices of each member, pact signatures.
- Private clauses of an organization and generated contract drafts.
On an organization's public page, partner payment appears only as a rate and a count — “100% confirmed · 4 partners” — never an amount. See the revenue split.
Pagination and rate
Reuse meta.next_cursor in the cursor parameter. The maximum is 50 items per page. The default limit is 120 requests per minute per key; the X-RateLimit-* headers report the window state.
The organization's monthly quota is 1,000 calls on Base, 10,000 on Alpha and 100,000 on Clan. The X-Monthly-Quota-* headers report the balance and the reset. Base and Alpha allow one active key; Clan allows five.
Machine contract
Open the OpenAPI 3.1 document · Webhook documentation · HubSpot and Notion recipes
For continuous synchronization, combine API reads with the need.* and event.* webhook cycles.
MCP connector for AI assistants beta
AI assistants (Claude, ChatGPT, a company agent) can query Xoolink live through the Model Context Protocol. Read-only, no key or account, public data only.
https://xoolink.com/mcp
search_organizations: find organizations by capability, sector, location or network.get_organization: read a public profile and its proof, as counts, never amounts.compose_team: propose a complementary team for a need, with coverage and gaps.explain_xoolink: answer with the FAQ’s answers and their links.searchandfetch: the shape ChatGPT’s deep research expects.
Add the connector. In Claude or ChatGPT, add a custom connector (remote MCP server) with the address above.
What never leaves. Demo, incomplete or “Do not list” organizations; people, posts, needs and events, quotes and pacts. The text of a need sent to compose_team is not stored. Details in the privacy policy, section 4a.
Limits. 60 calls per minute per address, 20 team compositions per hour. Teams are proposals: no organization is contacted.
Acting on behalf of a member
A second address lets an assistant act with a member’s account, after their explicit consent:
https://xoolink.com/mcp/membre
Added as a connector, it opens a Xoolink page where the member sees which application asks for access, where it will send them back, and what it will be able to do. They accept or decline (OAuth 2.1 with PKCE and dynamic client registration).
my_account: read their name, profile address and organizations.my_invitations: read their pending invitations to join a team; accepting or declining happens on Xoolink.draft_need: prepare a need as a draft. Nothing is published: the member opens the returned link, reviews and publishes it themselves.
The assistant can never post, send a message, sign a pact or submit a quote. Every action taken on the member’s behalf is logged. They withdraw an access at any time in Settings › Integrations › Connected apps; changing their password or signing out everywhere withdraws it too.