RendezvuDocs
    DocsBrand API

    Brand API

    Pull your brand's Rendezvu data into your own systems with an authenticated, read-only REST API. Sales, clicks, campaigns, content, roster, gifts, codes and surveys.

    OverviewUpdated
    On this page
    • Make your first request
    • Every endpoint
    • What the API never returns
    • Server-side only
    • Machine-readable spec

    The Rendezvu Brand API is organized around REST. It has predictable resource URLs, takes its options as query parameters, returns JSON in one envelope, and uses standard HTTP status codes and Bearer authentication. It is built for one job: getting your own Rendezvu data into your warehouse, your BI tool, your CRM or a page rendered on your server.

    Three rules shape everything else in this reference. The API is read-only: every endpoint is a GET. It is server-to-server: keys live on your server, never in a browser or an app. And it is scoped to one brand per key: a key reads the brand that created it and nothing else, so there is no brand id to pass and no way to ask for another brand's data.

    text
    Base URL   https://api.rendezvu.co/api/brand/v1
    Auth       Authorization: Bearer rdz_sk_...
    Methods    GET and HEAD
    Format     JSON, UTF-8, ISO 8601 dates in UTC

    Make your first request#

    1. In your Rendezvu console, open Settings, then Integrations, then Brand API, and create a key with the scopes you need. Copy the secret when it appears: it is shown once.
    2. Store it in your secret manager or environment as RENDEZVU_BRAND_API_KEY.
    3. Call /me. It needs no scope, so it answers for every valid key and tells you which brand and scopes the key carries.
    bash
    curl https://api.rendezvu.co/api/brand/v1/me \
      -H "Authorization: Bearer $RENDEZVU_BRAND_API_KEY"
    json
    {
      "success": true,
      "data": {
        "brand": { "id": "3d9a7c1e-5b2f-4a8d-9e6c-1f0b2a3c4d5e", "name": "Northfork Gear Co." },
        "key": {
          "id": "0f9e8d7c-6b5a-4c3d-9e2f-1a0b9c8d7e6f",
          "scopes": ["analytics:read", "content:read"],
          "expires_at": "2027-01-06T17:42:10.000Z"
        }
      },
      "_timing": { "duration_ms": 12 }
    }

    A 200 means the key works. A 401 means it is wrong, expired or revoked; see Authentication.

    Every endpoint#

    EndpointScopeDoes
    GET /menoneRetrieve the current brand and key
    GET /analytics/clicksanalytics:readRetrieve click analytics
    GET /analytics/hostsanalytics:readList host performance
    GET /ordersanalytics:readList orders
    GET /opportunitiesopportunities:readList opportunities
    GET /opportunities/{id}opportunities:readRetrieve an opportunity
    GET /contentcontent:readList content
    GET /content/{source}/{item_id}/downloadcontent:readRetrieve a download URL
    GET /rosterroster:readList roster hosts
    GET /recommendationsrecommendations:readList recommendations
    GET /giftsgifts:readList gifts
    GET /codescodes:readList discount codes
    GET /surveyssurveys:readList surveys
    GET /surveys/{id}/resultssurveys:readRetrieve survey results

    What the API never returns#

    Some data stays in the console by design, with no scope that unlocks it:

    • Messages between your team and hosts, and the files attached to them.
    • Host contact details: email, phone, shipping address and gift tracking numbers.
    • Your team's internal notes: roster notes, host tags and internal campaign comments.
    • Billing: invoices, payment methods and credits.
    • Raw store and network payloads: order line items are reduced to title, variant, SKU, quantity and price.

    Server-side only#

    Never put a key in a browser or an app

    API responses carry no CORS headers for your domains, so a call from a web page fails by design. Call the API from your server, a scheduled job or your data pipeline, and send your own front end only what it needs to show.

    Machine-readable spec#

    The whole reference is also an OpenAPI 3.1 document at /docs/api/openapi.json, generated from the same source as these pages. Import it into Postman or Insomnia, generate a typed client, or hand it to a coding agent. Every page here also has a Markdown version: add .md to its URL.

    Fundamentals

    Authentication

    Authenticate every request with a secret API key in the Authorization header. Keys are read-only, scoped, tied to one brand, and always expire.

    Errors

    The Brand API uses conventional HTTP status codes. 2xx means success, 4xx means something in the request needs to change, and 5xx means retry later.

    Pagination and requests

    Every response shares one JSON envelope. List endpoints page with page and per_page, query parameters are strict, and every date is ISO 8601 in UTC.

    Rate limits

    Each API key can make 60 requests a minute, and each IP address 120. Every response carries headers that say how much of the limit is left.

    Versioning and changelog

    The API version is in the path. Additive changes ship into v1; a breaking change would ship as a new version. What changed, and when.

    Brand and key

    Retrieve the brand an API key belongs to and the key's scopes and expiry. The first call to make with a new key, and the cheapest health check.

    Analytics

    Campaigns

    Hosts

    Programs

    © 2026 Rendezvu, Inc.