Skip to content
Public endpoints

What you can actually call

Conseto has no general-purpose API for custom integrations yet. Most of the work is done by the script. This page lists the endpoints that exist and can be called directly, who may call them and the limits.

Base URLhttps://api.conseto.io

The script does this for you

Paste one script tag on any site. It shows the cookie banner, waits for consent and sends events on its own. You do not call an endpoint for that, and there is nothing to authenticate in the browser.

HTML
<script src="https://www.conseto.io/dist/conseto.min.js"></script>
<script>
  Conseto.init({ clientId: 'conseto_xxx_xxx' });
</script>

For the record, the script calls three endpoints: GET /api/consent/sdk-settings/:clientId for the project's settings, POST /api/v2/collect for events and POST /api/v2/collect/heartbeat for the install check. They are public and validated by the project ID, and they are not meant to be called by hand. There is no POST /api/collect.

Without a key

GET /api/pixel/:clientId
A 1x1 transparent GIF. Put it in an e-mail or newsletter to record an open. Query: t the kind (default pixel_impression), c a campaign, r a recipient. It always answers with the image.
GET /api/links/r/:shortCode
A tracked short link. Records the click (device, referrer) and redirects with 302 to the destination with the link's UTM parameters added. 404 for an unknown link, 410 for one that expired.
HTML
<img src="https://api.conseto.io/api/pixel/conseto_xxx_xxx?t=email_open&c=autumn-sale"
     width="1" height="1" alt="">

With your project's API key

Send the key in the x-api-key header (or as Authorization: Bearer). Send the project ID as client_id in the body, in the query or in the x-client-id header. You find the key in the project's detail in the app. Only the project's admin sees it and can renew it.

POST /api/proxy/track
Records up to 50 events in one request. Each event takes event_name (or n), properties (or d), page, referrer and a millisecond timestamp. Without a session_id and visitor_id they are filled in for you. Answers { success, processed, events }.
POST /api/proxy/identify
Links a visitor_id to your own user_id. An e-mail in traits is stored as a hash, never as text.
GET /api/proxy/ecommerce/products
Read only. For each product (item_id) the counts of view_item, add_to_cart, begin_checkout and purchase, and the revenue of the purchases, between from and to (default: the last 90 days). It counts only visits that are not bots and that gave analytics consent, so it is lower than your own server's count.
GET /api/proxy/health
Answers { status: ok }. No key.
curl
curl -X POST https://api.conseto.io/api/proxy/track \
  -H "Content-Type: application/json" \
  -H "x-api-key: csk_your_api_key" \
  -d '{
    "client_id": "conseto_xxx_xxx",
    "session_id": "your-session-id",
    "visitor_id": "your-visitor-id",
    "events": [
      { "event_name": "order_created", "properties": { "value": 49 }, "page": "https://your-site.com/checkout" }
    ]
  }'
curl
curl -X POST https://api.conseto.io/api/proxy/identify \
  -H "Content-Type: application/json" \
  -H "x-api-key: csk_your_api_key" \
  -d '{ "client_id": "conseto_xxx_xxx", "visitor_id": "your-visitor-id", "user_id": "user_42" }'
curl
curl "https://api.conseto.io/api/proxy/ecommerce/products?client_id=conseto_xxx_xxx&from=2026-09-01&to=2026-09-30" \
  -H "x-api-key: csk_your_api_key"

Through your own domain

To keep ad blockers from seeing a foreign domain, give the script the address of your own path as proxyUrl. It replaces https://api.conseto.io/api as the base of the script's three calls. Your server then forwards that path to https://api.conseto.io/api and passes the body on.

Limits

A request over a limit gets 429 with { error, code: "RATE_LIMITED", retryAfter }.

General
1,000 requests per 15 minutes per IP address, for the script's calls, the project proxy and the consent endpoints.
Pixel and short links
120 requests per minute per IP address.
Per project, from the script
A ceiling on what one project can send in 15 minutes: 2,000 requests on Free and Starter, 4,000 on Business, 20,000 on Enterprise.
Visits per site
Free allows 10,000 visits per site in 30 days, Starter and Business 100,000, Enterprise has no cap. Beyond that a new visit gets 429 with SESSION_LIMIT_EXCEEDED. Visits already under way continue.
MCP
30 requests per minute per key, and 120 per minute per IP address before the key is checked.

For AI assistants: MCP

The closest thing Conseto has to a data API today is MCP: connect Claude Code, Cursor or claude.ai to api.conseto.io/mcp and ask about traffic, consent, search and audits in your own words. Read only, one key per project, on the Business plan and up.

Read the MCP setup guide

Coming later

Not built yet, so not something you can wire up today:

  • A general REST API and an OpenAPI specification
  • Outgoing webhooks for your own systems
  • Server-side SDKs for Node.js, Python and PHP
  • MCP over OAuth for clients we have not tested (ChatGPT, Claude Desktop)

Read next

Checked against the code on 1 October 2026.

Missing something?

This is everything we document today, and each page says only what the script and the gateway do now. If you need a guide that is not here, tell us what you want to achieve.

Write to us