Skip to main content
The repository includes a safe acceptance harness at backend/scripts/public_api_acceptance.py.

Read-only checks

Set an API key for an isolated or read-only workspace and run:
This checks authenticated reads and verifies that a missing key returns 401. It does not create records, launch campaigns, send messages, make calls, or alter configuration.

Synthetic mutation check

Only run this against a disposable workspace with a synthetic email address:
The mutation suite is intentionally limited to creating one synthetic lead. It does not launch, publish, send, call, charge, delete, or change partner configuration.

Release gate

Record the API commit, workspace used, key rotation status, result output, and date. Compare failures against the endpoint coverage matrix before changing documentation. Never paste API keys into issue reports or CI logs.