API, MCP and webhooks
Connect your own tools and AI assistants to a workspace — API keys, the API, MCP for assistants such as Claude, webhooks and the limits.
API & MCP, in the menu under Account, connects the workspace you're in to your own tools — a CRM, Make, n8n, Zapier — and to AI assistants such as Claude. It's part of the Unlimited plan (plans).
Leads stay in SalesBullet: through the API and MCP you find people and add them to your contacts and campaigns, but their emails and phone numbers aren't shown. To take leads out, use a CSV export (exports).
API keys
Only the workspace's owner makes keys; everyone in the workspace sees the list.
- Type a name for the key — what it's for, such as "CRM sync" — and click Create key.
- Copy the key right away: it's shown only now. The list keeps just its first characters.
- Revoke stops a key at once — for example one you shared by mistake.
A key works as the person who made it, in this workspace. It stops working if they leave the workspace, or if the account moves to the Free plan.
The API
Send your key in the X-API-Key header to https://salesbullet.ai/api/v1. The API reference link on the page
lists every call with its fields, and lets you try them.
curl https://salesbullet.ai/api/v1/campaigns -H "X-API-Key: sb_your_key"
| Part | What you can do |
|---|---|
| Lists | Make lists and add your own contacts to them — up to 1,000 a call, matched on email |
| Contacts | Set fields on a contact, such as an icebreaker your own tool wrote — custom fields become variables in your messages; delete a contact |
| Campaigns | Their numbers; add lists; start and pause; stop, pause or resume one lead by email — for example when your CRM says they're a customer now |
| Do-not-contact list | Add emails and whole domains, list and remove them |
| Webhooks | Add, list and delete them — see below |
Every refusal answers with a short reason: {"error": "…"}.
MCP — SalesBullet in your AI assistant
With MCP, an AI assistant works in your workspace: it counts and searches leads and companies, adds people to a contact list, adds a list to a campaign, starts or pauses a campaign and reports its numbers. It sees who people are — never their emails or phone numbers.
- An assistant that takes a header: the address
https://salesbullet.ai/mcp, with your key in theX-API-Keyheader. - An assistant that only takes a link — such as Claude's custom connectors: the MCP link shown with a new key,
https://salesbullet.ai/k/your-key/mcp.
Warning
The MCP link has your key in it: keep it as private as the key.
Webhooks
A webhook posts your campaigns' events to your address as they happen — to your CRM, Make, n8n or Zapier. Only the workspace's owner adds webhooks.
- Paste the address. It must start with
https://. - Untick the events you don't need.
- Click Add webhook and copy its signing secret — it's shown only now.
| Event | When |
|---|---|
email.sent |
A campaign email went out |
reply.received |
A lead replied |
lead.label_changed |
A conversation got a label — from your team or AI labels |
lead.bounced |
An email bounced |
lead.unsubscribed |
A lead unsubscribed |
lead.completed |
A lead finished the sequence |
Each event names the campaign and the lead — name, job title, company, LinkedIn profile. A person from our lead database
comes with their email only once they've replied (reply.received, lead.label_changed); your own contacts always
come with theirs.
Each request has an X-SalesBullet-Signature header: sha256= and the HMAC-SHA256 of the X-SalesBullet-Timestamp
header, a dot and the body, made with the signing secret. Check it to know the event came from SalesBullet. If your
address doesn't answer with a 2xx status, SalesBullet tries again — up to 10 times over about 40 minutes, with the same
X-SalesBullet-Event-Id. The page shows the last delivery, or the last error, next to each webhook.
Limits
Each key makes up to 120 calls a minute, 2,000 an hour and 20,000 a day — the API and MCP together. Over that, the
answer is 429 Too Many Requests, and its Retry-After header says how many seconds to wait.