← Xoolink

Xoolink public API v1 · beta

Connect a server, a cloud function or your automation tool to your Xoolink organization's public data.

Read-only. Messages, quotes, pacts, confidential needs and internal data are never exposed. Never put a key in browser or mobile code.

API v1 serves the public side: open needs, public events, and your organization's page. Everything that lives inside a pack stays inside.

1. Create a key

In Xoolink: organization page → Admin dashboard → Public API · beta. Choose the permissions and the expiry, then copy the key — it is shown only once.

2. Authenticate

Authorization: Bearer xool_live_...

3. Read the resources

GET /api/v1/organizationorganization:read

Public page of the organization tied to the key.

GET /api/v1/opportunitiesopportunities:read

Recent public opportunities, with cursor pagination.

GET /api/v1/opportunities/:idopportunities:read

Current state of one opportunity. Returns 404 if it is no longer public.

GET /api/v1/eventsevents:read

Public events, with cursor pagination.

GET /api/v1/events/:idevents:read

Current state of one event. Returns 404 if it is no longer public.

curl https://xoolink.com/api/v1/organization \
  -H "Authorization: Bearer $XOOLINK_API_KEY"

curl "https://xoolink.com/api/v1/opportunities?limit=20" \
  -H "Authorization: Bearer $XOOLINK_API_KEY"

curl "https://xoolink.com/api/v1/opportunities/req-123" \
  -H "Authorization: Bearer $XOOLINK_API_KEY"

curl "https://xoolink.com/api/v1/events?limit=20" \
  -H "Authorization: Bearer $XOOLINK_API_KEY"

curl "https://xoolink.com/api/v1/events/event-123" \
  -H "Authorization: Bearer $XOOLINK_API_KEY"

What is never exposed

These objects have no endpoint in the API, today or in any other form: they are readable only by members of the pack or organization concerned.

On an organization's public page, partner payment appears only as a rate and a count — “100% confirmed · 4 partners” — never an amount. See the revenue split.

Pagination and rate

Reuse meta.next_cursor in the cursor parameter. The maximum is 50 items per page. The default limit is 120 requests per minute per key; the X-RateLimit-* headers report the window state.

The organization's monthly quota is 1,000 calls on Base, 10,000 on Alpha and 100,000 on Clan. The X-Monthly-Quota-* headers report the balance and the reset. Base and Alpha allow one active key; Clan allows five.

Machine contract

Open the OpenAPI 3.1 document · Webhook documentation · HubSpot and Notion recipes

For continuous synchronization, combine API reads with the need.* and event.* webhook cycles.

MCP connector for AI assistants beta

AI assistants (Claude, ChatGPT, a company agent) can query Xoolink live through the Model Context Protocol. Read-only, no key or account, public data only.

https://xoolink.com/mcp

Add the connector. In Claude or ChatGPT, add a custom connector (remote MCP server) with the address above.

What never leaves. Demo, incomplete or “Do not list” organizations; people, posts, needs and events, quotes and pacts. The text of a need sent to compose_team is not stored. Details in the privacy policy, section 4a.

Limits. 60 calls per minute per address, 20 team compositions per hour. Teams are proposals: no organization is contacted.

Acting on behalf of a member

A second address lets an assistant act with a member’s account, after their explicit consent:

https://xoolink.com/mcp/membre

Added as a connector, it opens a Xoolink page where the member sees which application asks for access, where it will send them back, and what it will be able to do. They accept or decline (OAuth 2.1 with PKCE and dynamic client registration).

The assistant can never post, send a message, sign a pact or submit a quote. Every action taken on the member’s behalf is logged. They withdraw an access at any time in Settings › Integrations › Connected apps; changing their password or signing out everywhere withdraws it too.