Dripcel
MARKETING · MARKETING
SMS campaigns, contacts, targeting checks, and credit balance in the account they connected.
Acts as the person, not as itself
Each user connects their own account. Every call carries both identities — the agent and the person it is acting for — so the agent can never reach past what that individual can already do.
Credentials never touch the agent
Tokens live in the vault and attach server-side at call time. The agent holds a session, not a secret, and revoking access does not mean rotating a key.
Every call on the record
Who asked, which agent acted, which action ran, and the verdict that let it through — one audit trail across every integration, not one per vendor.
What an agent can do
Each action is granted on its own. An agent allowed to read is not thereby allowed to write, and the scope beside each row is what the acting user must have connected for it to run at all.
dripcel_delete_contacts_by_cellWRITEDelete a contact via DELETE /contacts/{cell}. Deletes one contact by cell number. DESTRUCTIVE and not reversible through this API: Dripcel publishes no undelete, and the contact's history goes with it. An unparseable number answers 400 `"Invalid cell number"` and a number with no contact answers 404 `"Contact not found"`. To confirm a deletion, read the contact back and expect that 404 -- absence is a status question, not something the delete's own reply can prove. Deleting is rarely what a compliance workflow wants. To stop messaging someone, OPT THEM OUT (`dripcel_post_contacts_by_cell_optOut` with `all: true`) -- that keeps the suppression record, while deleting the contact discards it. Requires the `contact.delete` permission on the API key. Measured 2026-09-23: a key without it answers 403 naming `contact.delete`. It is NOT nested under `contact.update`, so a key that may edit contacts cannot necessarily delete one. Every Dripcel reply is `{ok: true, data}` or `{ok: false, error}`, so a 200 carrying `ok: false` is an application error rather than a success. Dripcel rate-limits to about 50 requests per minute PER ORGANISATION and answers 429 `{ok: false, error: {resetsAt, remaining}}`; that is the organisation's shared budget, never the credential. A 403 names the API-key permission it wanted (`Insufficient permissions. Must have the '<name>' permission(s)`) and means the key was minted without it -- regenerate or modify the key under Profile > API Keys rather than retrying.
dripcel_delete_tags_by_tag_idWRITEDelete a tag via DELETE /tags/{tag_id}. Deletes one tag. DESTRUCTIVE, and wider than it looks: Dripcel's own danger callout says this "will also remove the tag from all contacts and campaigns that have it". A campaign whose targeting selects on that tag therefore changes WHO IT SENDS TO as a side effect of this call, and there is no undelete. To confirm a deletion, list the tags and check for absence rather than reading the tag back. Requires the `tag.delete` permission on the API key. Measured 2026-09-23: a key without it answers 403 naming `tag.delete`. It is NOT nested under `tag.read`. Every Dripcel reply is `{ok: true, data}` or `{ok: false, error}`, so a 200 carrying `ok: false` is an application error rather than a success. Dripcel rate-limits to about 50 requests per minute PER ORGANISATION and answers 429 `{ok: false, error: {resetsAt, remaining}}`; that is the organisation's shared budget, never the credential. A 403 names the API-key permission it wanted (`Insufficient permissions. Must have the '<name>' permission(s)`) and means the key was minted without it -- regenerate or modify the key under Profile > API Keys rather than retrying.
dripcel_get_balanceREADRead the credit balance via GET /balance. Returns the organisation's Dripcel credit balance as a bare number in `data`. It takes no arguments, touches no contact data and is the cheapest authenticated read on the API, which is why it is the endpoint a pasted key is probed against. Call this BEFORE the two credit-metered tools (contact search and the compliance check): they spend this number, and Dripcel answers 402 `"Insufficient balance"` when it runs out. Dripcel documents no permission for this endpoint, and it is NOT assumed to be open: on 2026-09-23 a key holding NONE of Dripcel's sixteen permissions reached it successfully, which is what an ungated endpoint looks like and what a gated one cannot do. Recorded as measured rather than asserted. Measured here directly: this endpoint answered 200 `{"ok":true,"data":35}` to that same permissionless key. Every Dripcel reply is `{ok: true, data}` or `{ok: false, error}`, so a 200 carrying `ok: false` is an application error rather than a success. Dripcel rate-limits to about 50 requests per minute PER ORGANISATION and answers 429 `{ok: false, error: {resetsAt, remaining}}`; that is the organisation's shared budget, never the credential. A 403 names the API-key permission it wanted (`Insufficient permissions. Must have the '<name>' permission(s)`) and means the key was minted without it -- regenerate or modify the key under Profile > API Keys rather than retrying.
dripcel_get_campaignsREADList campaigns via GET /campaigns. Lists the organisation's campaigns in the ORIGINAL `Campaign` model. Newer campaigns are stored in the richer, nested `Campaigns V2` model and served on the separate `/campaigns/v2` routes, so this list is not necessarily every campaign the account has -- read both when you need a complete picture. Requires the `campaign.read.config` permission on the API key. Measured 2026-09-23: a key without it answers 403 naming `campaign.read.config`. Every Dripcel reply is `{ok: true, data}` or `{ok: false, error}`, so a 200 carrying `ok: false` is an application error rather than a success. Dripcel rate-limits to about 50 requests per minute PER ORGANISATION and answers 429 `{ok: false, error: {resetsAt, remaining}}`; that is the organisation's shared budget, never the credential. A 403 names the API-key permission it wanted (`Insufficient permissions. Must have the '<name>' permission(s)`) and means the key was minted without it -- regenerate or modify the key under Profile > API Keys rather than retrying.
dripcel_get_campaigns_by_campaign_idREADRead a campaign via GET /campaigns/{campaign_id}. Reads one campaign in the original `Campaign` model. A campaign stored in the V2 model is served by the `/campaigns/v2/{campaign_id}` tool instead. A campaign id Dripcel cannot resolve answers 404 `"Campaign not found"`. Requires the `campaign.read.config` permission on the API key. Measured 2026-09-23: a key without it answers 403 naming `campaign.read.config`. Every Dripcel reply is `{ok: true, data}` or `{ok: false, error}`, so a 200 carrying `ok: false` is an application error rather than a success. Dripcel rate-limits to about 50 requests per minute PER ORGANISATION and answers 429 `{ok: false, error: {resetsAt, remaining}}`; that is the organisation's shared budget, never the credential. A 403 names the API-key permission it wanted (`Insufficient permissions. Must have the '<name>' permission(s)`) and means the key was minted without it -- regenerate or modify the key under Profile > API Keys rather than retrying.
dripcel_get_campaigns_v2READList V2 campaigns via GET /campaigns/v2. Lists the organisation's `Campaigns V2` campaigns -- the newer, nested model carrying `targeting` (tag and segment `$in`/`$nin` sets, optional proportional tag `weights`, and event predicates), per-channel `sms` and `email` configuration, the tracking link, hooks, recurring-send windows, financials, legal confirmations, a `marketplace` block when the campaign came from an offer, and optimisation settings. A V2 campaign is always returned in full: Dripcel documents that field projection and the `format` query parameter are not supported on these routes. Requires the `campaign.read.config` permission on the API key. Measured 2026-09-23: a key without it answers 403 naming `campaign.read.config`. Every Dripcel reply is `{ok: true, data}` or `{ok: false, error}`, so a 200 carrying `ok: false` is an application error rather than a success. Dripcel rate-limits to about 50 requests per minute PER ORGANISATION and answers 429 `{ok: false, error: {resetsAt, remaining}}`; that is the organisation's shared budget, never the credential. A 403 names the API-key permission it wanted (`Insufficient permissions. Must have the '<name>' permission(s)`) and means the key was minted without it -- regenerate or modify the key under Profile > API Keys rather than retrying.
dripcel_get_campaigns_v2_by_campaign_idREADRead a V2 campaign via GET /campaigns/v2/{campaign_id}. Reads one `Campaigns V2` campaign in full. A campaign id Dripcel cannot resolve answers 404 `"Campaign not found"` -- a missing record, not a missing route, because this host matches the route before it authenticates or looks anything up. Requires the `campaign.read.config` permission on the API key. Measured 2026-09-23: a key without it answers 403 naming `campaign.read.config`. Every Dripcel reply is `{ok: true, data}` or `{ok: false, error}`, so a 200 carrying `ok: false` is an application error rather than a success. Dripcel rate-limits to about 50 requests per minute PER ORGANISATION and answers 429 `{ok: false, error: {resetsAt, remaining}}`; that is the organisation's shared budget, never the credential. A 403 names the API-key permission it wanted (`Insufficient permissions. Must have the '<name>' permission(s)`) and means the key was minted without it -- regenerate or modify the key under Profile > API Keys rather than retrying.
dripcel_get_contacts_by_cellREADRead a contact via GET /contacts/{cell}. Reads one contact by cell number, including the personally identifying fields -- which is what its permission name says. An unparseable number answers 400 `"Invalid cell number"` and a number with no contact answers 404 `"Contact not found"`, so the two failures are distinguishable. Requires the `contact.read.pii` permission on the API key. Measured 2026-09-23: a key without it answers 403 naming `contact.read.pii`. Every Dripcel reply is `{ok: true, data}` or `{ok: false, error}`, so a 200 carrying `ok: false` is an application error rather than a success. Dripcel rate-limits to about 50 requests per minute PER ORGANISATION and answers 429 `{ok: false, error: {resetsAt, remaining}}`; that is the organisation's shared budget, never the credential. A 403 names the API-key permission it wanted (`Insufficient permissions. Must have the '<name>' permission(s)`) and means the key was minted without it -- regenerate or modify the key under Profile > API Keys rather than retrying.
dripcel_get_deliveriesREADList deliveries via GET /deliveries. Reads delivery records. Neither parameter is required on its own, but AT LEAST ONE must be given: `cell` for one contact's deliveries, or `customerId` for the deliveries of one send (the `customerId` the SMS-send tool returns). A call with neither answers 400. Requires the `delivery.read` permission on the API key. Measured 2026-09-23: a key without it answers 403 naming `delivery.read`. Every Dripcel reply is `{ok: true, data}` or `{ok: false, error}`, so a 200 carrying `ok: false` is an application error rather than a success. Dripcel rate-limits to about 50 requests per minute PER ORGANISATION and answers 429 `{ok: false, error: {resetsAt, remaining}}`; that is the organisation's shared budget, never the credential. A 403 names the API-key permission it wanted (`Insufficient permissions. Must have the '<name>' permission(s)`) and means the key was minted without it -- regenerate or modify the key under Profile > API Keys rather than retrying.
dripcel_get_email_templatesREADList email templates via GET /email/templates. Lists the organisation's email templates as `data.templates`. Their `_id` values are what the bulk-email tool's `template_id` takes. It is the only template operation this API exposes: Dripcel's page describes creating, updating and deleting templates, but publishes no route for any of them. Dripcel documents no permission for this endpoint, and it is NOT assumed to be open: on 2026-09-23 a key holding NONE of Dripcel's sixteen permissions reached it successfully, which is what an ungated endpoint looks like and what a gated one cannot do. Recorded as measured rather than asserted. Measured here directly: this endpoint answered 200 `{"ok":true,"data":{"templates":[]}}` to that same permissionless key. Every Dripcel reply is `{ok: true, data}` or `{ok: false, error}`, so a 200 carrying `ok: false` is an application error rather than a success. Dripcel rate-limits to about 50 requests per minute PER ORGANISATION and answers 429 `{ok: false, error: {resetsAt, remaining}}`; that is the organisation's shared budget, never the credential. A 403 names the API-key permission it wanted (`Insufficient permissions. Must have the '<name>' permission(s)`) and means the key was minted without it -- regenerate or modify the key under Profile > API Keys rather than retrying.
dripcel_get_exchange_buyer_transaction_createWRITEConfirm one marketplace lead by postback via GET /exchange/buyer/transaction/create. Confirms a SINGLE marketplace lead through a GET, which is the shape a landing page or webhook postback can reach. It takes the same values as the bulk create tool, as query parameters: exactly one of `campaign_id`, `send_id` or `click_id`, plus `resource_id` and `cell`, and optionally the `status` to land on. AUTHENTICATES DIFFERENTLY FROM EVERY OTHER DRIPCEL TOOL. This endpoint reads the API key from the `key` QUERY PARAMETER and ignores the Authorization header entirely -- measured 2026-09-23: `Authorization: Bearer <real key>` answers 401 `"No key provided"`, while `?key=<real key>` with no header at all is accepted. Agentic Fabriq attaches `key` server-side for this tool only; it is NOT an argument, and a `key` you pass would be ignored. It is Dripcel's browser/webhook postback form of the POST tool beside it, which is the one to prefer from an agent: the POST takes a batch, keeps the secret out of the URL, and needs the same permission. MOVES MONEY on `status: "completed"`, with the same duplicate and cap protections as the bulk create tool. Requires the `marketplace_transaction.create` permission on the API key. Measured 2026-09-23: with `?key=<real key>` and nothing else, this endpoint answers 403 naming `marketplace_transaction.create` -- the SAME permission as the POST tool. Dripcel's documentation prints no permission line for this route and the hand-built ledger recorded none; the live API is what settles it. Every Dripcel reply is `{ok: true, data}` or `{ok: false, error}`, so a 200 carrying `ok: false` is an application error rather than a success. Dripcel rate-limits to about 50 requests per minute PER ORGANISATION and answers 429 `{ok: false, error: {resetsAt, remaining}}`; that is the organisation's shared budget, never the credential. A 403 names the API-key permission it wanted (`Insufficient permissions. Must have the '<name>' permission(s)`) and means the key was minted without it -- regenerate or modify the key under Profile > API Keys rather than retrying.
dripcel_get_sales_createWRITERecord one sale by postback via GET /sales/create. Records a SINGLE sale through a GET, which is the shape a thank-you page or webhook postback can reach. It takes the same values as the bulk upload tool, as query parameters. For a `Campaigns V2` campaign the cell must be in international format. The same 404 (unknown campaign) and 409 (`"Duplicate sale"`) apply. AUTHENTICATES DIFFERENTLY FROM EVERY OTHER DRIPCEL TOOL. This endpoint reads the API key from the `key` QUERY PARAMETER and ignores the Authorization header entirely -- measured 2026-09-23: `Authorization: Bearer <real key>` answers 401 `"No key provided"`, while `?key=<real key>` with no header at all is accepted. Agentic Fabriq attaches `key` server-side for this tool only; it is NOT an argument, and a `key` you pass would be ignored. It is Dripcel's browser/webhook postback form of the POST tool beside it, which is the one to prefer from an agent: the POST takes a batch, keeps the secret out of the URL, and needs the same permission. Requires the `sale.create` permission on the API key. Measured 2026-09-23: with `?key=<real key>` and nothing else, this endpoint answers 403 naming `sale.create` -- the SAME permission as the POST tool. Dripcel's documentation prints its permission line above the POST heading and none at this one, and the hand-built ledger recorded none; the live API is what settles it. Every Dripcel reply is `{ok: true, data}` or `{ok: false, error}`, so a 200 carrying `ok: false` is an application error rather than a success. Dripcel rate-limits to about 50 requests per minute PER ORGANISATION and answers 429 `{ok: false, error: {resetsAt, remaining}}`; that is the organisation's shared budget, never the credential. A 403 names the API-key permission it wanted (`Insufficient permissions. Must have the '<name>' permission(s)`) and means the key was minted without it -- regenerate or modify the key under Profile > API Keys rather than retrying.
dripcel_get_send_logs_by_send_idREADRead a send log via GET /send-logs/{send_id}. Reads one send's metadata: the campaign it belongs to, the UNRESOLVED template that was sent, why it was triggered, when delivery started, and its destinations. `group_destinations` decides what `destinations` is -- `count` for the number of contacts, `list` for the actual cell numbers. An unknown send id answers 404 `{"code":"resource_not_found"}`. `group_destinations=list` returns every recipient's cell number, which is contact PII in a tool whose permission is only `sendLog.read`. Ask for it when you need it, not by default. Requires the `sendLog.read` permission on the API key. Measured 2026-09-23: a key without it answers 403 naming `sendLog.read`. Note the camelCase -- Dripcel's permission vocabulary is not internally consistent and this is the provider's own spelling. Every Dripcel reply is `{ok: true, data}` or `{ok: false, error}`, so a 200 carrying `ok: false` is an application error rather than a success. Dripcel rate-limits to about 50 requests per minute PER ORGANISATION and answers 429 `{ok: false, error: {resetsAt, remaining}}`; that is the organisation's shared budget, never the credential. A 403 names the API-key permission it wanted (`Insufficient permissions. Must have the '<name>' permission(s)`) and means the key was minted without it -- regenerate or modify the key under Profile > API Keys rather than retrying.
dripcel_get_tagsREADList tags via GET /tags. Lists the organisation's tags. Their `_id` values are what every tag-taking tool prefers over tag NAMES, because a name can be changed and an id cannot. Requires the `tag.read` permission on the API key. Measured 2026-09-23: a key without it answers 403 naming `tag.read`. Every Dripcel reply is `{ok: true, data}` or `{ok: false, error}`, so a 200 carrying `ok: false` is an application error rather than a success. Dripcel rate-limits to about 50 requests per minute PER ORGANISATION and answers 429 `{ok: false, error: {resetsAt, remaining}}`; that is the organisation's shared budget, never the credential. A 403 names the API-key permission it wanted (`Insufficient permissions. Must have the '<name>' permission(s)`) and means the key was minted without it -- regenerate or modify the key under Profile > API Keys rather than retrying.
dripcel_get_tags_by_tag_idREADRead a tag via GET /tags/{tag_id}. Reads one tag by id. Requires the `tag.read` permission on the API key. Measured 2026-09-23: a key without it answers 403 naming `tag.read`. Every Dripcel reply is `{ok: true, data}` or `{ok: false, error}`, so a 200 carrying `ok: false` is an application error rather than a success. Dripcel rate-limits to about 50 requests per minute PER ORGANISATION and answers 429 `{ok: false, error: {resetsAt, remaining}}`; that is the organisation's shared budget, never the credential. A 403 names the API-key permission it wanted (`Insufficient permissions. Must have the '<name>' permission(s)`) and means the key was minted without it -- regenerate or modify the key under Profile > API Keys rather than retrying.
dripcel_post_compliance_sendWRITECheck cell numbers against a campaign's targeting via POST /compliance/send. Asks, for each cell number, whether it may be sent to -- against one campaign's targeting criteria when `campaign_id` is given, or against the organisation's global opt-outs when it is not. This is the endpoint a third-party supplier uses to stay compliant BEFORE it sends, and it answers `{cell, can_send}` per number plus the credits the check cost. SPENDS THE ORGANISATION'S CREDIT BALANCE: 0.14 credits per CELL QUERIED. Dripcel meters this endpoint separately from the rate limit, so a retry loop spends real money rather than hitting a 429. Read the balance first (`dripcel_get_balance`), batch what you can, and do not call this to probe whether a connection works. Dripcel answers 402 `"Insufficient balance"` when the balance cannot cover the batch, so a large `cells` array can fail as a whole. ONE FIELD NAME IS UNSETTLED: Dripcel's own page gives the required field as `cells` in its parameter table and as `cell` in the worked example directly below it. The table is followed here. This could not be settled against the live API -- the permission check runs first and the wave's key does not hold `compliance:send.create` -- so if Dripcel answers a validation error naming the field, send `cell` instead. Requires the `compliance:send.create` permission on the API key. Measured 2026-09-23: a key without it answers 403 naming `compliance:send.create` -- and the colon in that name is Dripcel's, not a typo. Fifteen of Dripcel's sixteen permissions separate their parts with dots and this one uses a colon; the 403 above is the provider spelling it back. Every Dripcel reply is `{ok: true, data}` or `{ok: false, error}`, so a 200 carrying `ok: false` is an application error rather than a success. Dripcel rate-limits to about 50 requests per minute PER ORGANISATION and answers 429 `{ok: false, error: {resetsAt, remaining}}`; that is the organisation's shared budget, never the credential. A 403 names the API-key permission it wanted (`Insufficient permissions. Must have the '<name>' permission(s)`) and means the key was minted without it -- regenerate or modify the key under Profile > API Keys rather than retrying.
dripcel_post_contactsWRITEUpload new contacts via POST /contacts. Creates contacts in bulk. This is the CREATE-ONLY upload: it does not touch an existing contact, takes up to 100,000 per request and spends fewer rate-limit credits than the update-capable upload. Use the update tool (`PUT /contacts`) when existing contacts must change. Field names are NOT mapped -- send Dripcel's own names, including the custom-field ids `c1`, `c2` and so on. The reply reports `validContacts` and an `invalidContacts` array carrying the 0-based `row` and the validation `issue` for each one rejected, so a partially valid upload is not an error. `send` is the one field to read twice: supplying it TRIGGERS A REAL SEND to the contacts this call uploads, attributed to `campaign_id` and rendered from `template`. That spends credits and messages real people. Omit it unless a send is what you mean. Requires the `contact.create` permission on the API key. Measured 2026-09-23: a key without it answers 403 naming `contact.create`. Dripcel's documentation covers POST and PUT on one line with different values -- `["contact.create"]` (for POST), `["contact.update"]` (for PUT) -- and the live API confirms the split in both directions. Every Dripcel reply is `{ok: true, data}` or `{ok: false, error}`, so a 200 carrying `ok: false` is an application error rather than a success. Dripcel rate-limits to about 50 requests per minute PER ORGANISATION and answers 429 `{ok: false, error: {resetsAt, remaining}}`; that is the organisation's shared budget, never the credential. A 403 names the API-key permission it wanted (`Insufficient permissions. Must have the '<name>' permission(s)`) and means the key was minted without it -- regenerate or modify the key under Profile > API Keys rather than retrying.
dripcel_post_contacts_by_cell_optOutWRITEOpt a contact out of campaigns via POST /contacts/{cell}/optOut. Opts one contact out of several campaigns at once, or -- with `all: true` -- out of every existing AND FUTURE campaign. This is the robust form of the pair; the PUT tool beside it opts out of exactly one campaign. Either `campaign_ids` or `all` must be given, or Dripcel answers 400 `"Must provider either campaign_ids or set 'all' flag to true"` (the typo is Dripcel's). `create_missing_contact` records the opt-out even for a cell number with no contact yet, which is what a suppression list normally wants. Requires the `contact.update.deduped_campaign_ids` permission on the API key. Measured 2026-09-23: a key without it answers 403 naming `contact.update.deduped_campaign_ids`. That permission is NESTED under `contact.update`, so a key holding `contact.update` reaches this endpoint too -- the reverse does not hold. Every Dripcel reply is `{ok: true, data}` or `{ok: false, error}`, so a 200 carrying `ok: false` is an application error rather than a success. Dripcel rate-limits to about 50 requests per minute PER ORGANISATION and answers 429 `{ok: false, error: {resetsAt, remaining}}`; that is the organisation's shared budget, never the credential. A 403 names the API-key permission it wanted (`Insufficient permissions. Must have the '<name>' permission(s)`) and means the key was minted without it -- regenerate or modify the key under Profile > API Keys rather than retrying.
dripcel_post_contacts_searchREADSearch contacts via POST /contacts/search. Runs a query over the organisation's contacts. `find`, `projection` and `options` use a SUBSET of MongoDB query syntax. At least one filter is required. By default only the contact id comes back -- name the fields you want in `projection`, each mapped to 1. SPENDS THE ORGANISATION'S CREDIT BALANCE: 10 credits PER REQUEST, whatever the result count. Dripcel meters this endpoint separately from the rate limit, so a retry loop spends real money rather than hitting a 429. Read the balance first (`dripcel_get_balance`), batch what you can, and do not call this to probe whether a connection works. So paginate with `options.skip`/`options.limit` deliberately: every page is another 10 credits. A 403 here can also be `"Insufficient Resource IDs"`, which names the tag or campaign ids the key may not reach rather than a missing permission. Requires the `contact.read.pii` permission on the API key. Measured 2026-09-23: a key without it answers 403 naming `contact.read.pii`, and it answers it BEFORE metering -- a call refused for permissions costs no credits. Every Dripcel reply is `{ok: true, data}` or `{ok: false, error}`, so a 200 carrying `ok: false` is an application error rather than a success. Dripcel rate-limits to about 50 requests per minute PER ORGANISATION and answers 429 `{ok: false, error: {resetsAt, remaining}}`; that is the organisation's shared budget, never the credential. A 403 names the API-key permission it wanted (`Insufficient permissions. Must have the '<name>' permission(s)`) and means the key was minted without it -- regenerate or modify the key under Profile > API Keys rather than retrying.
dripcel_post_contacts_updateWRITEBulk-update contacts via POST /contacts/update. Applies one update to every contact matching `find`. Both fields use a subset of MongoDB syntax, and `update` accepts EXACTLY ONE of `$addToSet` (add tag ids, or dedupe against campaign ids) and `$pull` (remove tag ids) -- Dripcel refuses a request carrying both. The reply reports `matchedCount`, `modifiedCount` and the `parsedRequest` it actually ran, which is the fastest way to see which defaults were filled in. SEPARATELY RATE-LIMITED, and Dripcel flags it in its own danger callout: "This endpoint is quite heavily rate-limited. Although you can update many contacts in one request, you can only make a limited number of requests per minute." That budget is tighter than the organisation's ~50/minute. Put the work in ONE call's `find` rather than looping, and back off on 429. Requires the `contact.update` permission on the API key. Dripcel documents `contact.update` for this endpoint. UNLIKE every other endpoint on this API it could not be confirmed live, because this one validates the body BEFORE it checks permissions -- measured 2026-09-23, an empty body and two progressively more valid ones all answered 400 ZodError rather than the 403 its sibling `PUT /contacts` answers for the same permission. Reaching the permission check needs a fully valid body, which needs real tag or campaign ids, which needs `tag.read`. Recorded as documented-but-unconfirmed rather than measured. Every Dripcel reply is `{ok: true, data}` or `{ok: false, error}`, so a 200 carrying `ok: false` is an application error rather than a success. Dripcel rate-limits to about 50 requests per minute PER ORGANISATION and answers 429 `{ok: false, error: {resetsAt, remaining}}`; that is the organisation's shared budget, never the credential. A 403 names the API-key permission it wanted (`Insufficient permissions. Must have the '<name>' permission(s)`) and means the key was minted without it -- regenerate or modify the key under Profile > API Keys rather than retrying.
dripcel_post_exchange_buyer_transactionWRITECreate marketplace lead transactions via POST /exchange/buyer/transaction. Confirms leads received against a marketplace offer, 1 to 1000 per request. THE BODY IS A JSON ARRAY, not an object. Each lead references the send it came from through EXACTLY ONE of `campaign_id`, `send_id` or `click_id` -- none or more than one is refused -- plus a buyer-supplied `resource_id` used for audit and idempotency. A lead that resolves to a non-marketplace campaign is rejected, and a batch with no matching offer answers 404 `"No matching marketplace offer for: ..."`. MOVES MONEY. `status: "completed"` credits the seller's wallet and debits your credits immediately; `pending` holds the lead for review with no wallet movement; `rejected` refuses it outright. Omitting `status` takes the offer's configured default. Two protections override what you ask for: a duplicate (same contact, same offer, within 7 days) is created `rejected` and NOT charged, and a lead that would exceed the offer's cap is held `pending`. The status a transaction actually landed on is only knowable by reading it back with the search tool. Requires the `marketplace_transaction.create` permission on the API key. Measured 2026-09-23: a key without it answers 403 naming `marketplace_transaction.create`. Every Dripcel reply is `{ok: true, data}` or `{ok: false, error}`, so a 200 carrying `ok: false` is an application error rather than a success. Dripcel rate-limits to about 50 requests per minute PER ORGANISATION and answers 429 `{ok: false, error: {resetsAt, remaining}}`; that is the organisation's shared budget, never the credential. A 403 names the API-key permission it wanted (`Insufficient permissions. Must have the '<name>' permission(s)`) and means the key was minted without it -- regenerate or modify the key under Profile > API Keys rather than retrying.
dripcel_post_exchange_buyer_transaction_searchREADSearch marketplace transactions via POST /exchange/buyer/transaction/search. Searches the buyer's marketplace transactions. Every filter is optional; an empty body returns the first page of everything. This is the tool that answers what status a lead ACTUALLY landed on, which the create tool cannot report -- duplicates and offer caps override the status you asked for. THE REPLY IS PAGINATED AND DRIPCEL'S PAGE DOES NOT SAY SO. Measured 2026-09-23, every reply carries a sibling `pagination` object (`limit`, `nextCursor`, `hasNext`) beside `data`. No request knob for it is documented, and neither a body `limit` nor a query `limit` changed the reported limit of 1000 on an empty account -- so read `hasNext` rather than assuming one page is everything, and treat `nextCursor` as the continuation token if Dripcel later documents where to send it. Dripcel documents no permission for this endpoint, and it is NOT assumed to be open: on 2026-09-23 a key holding NONE of Dripcel's sixteen permissions reached it successfully, which is what an ungated endpoint looks like and what a gated one cannot do. Recorded as measured rather than asserted. Measured here directly: this endpoint answered 200 `{"ok":true,"data":[],"pagination":{"limit":1000,"nextCursor":null,"hasNext":false}}` to that same permissionless key. Every Dripcel reply is `{ok: true, data}` or `{ok: false, error}`, so a 200 carrying `ok: false` is an application error rather than a success. Dripcel rate-limits to about 50 requests per minute PER ORGANISATION and answers 429 `{ok: false, error: {resetsAt, remaining}}`; that is the organisation's shared budget, never the credential. A 403 names the API-key permission it wanted (`Insufficient permissions. Must have the '<name>' permission(s)`) and means the key was minted without it -- regenerate or modify the key under Profile > API Keys rather than retrying.
dripcel_post_replies_searchREADSearch replies via POST /replies/search. Searches inbound replies. A `Reply` carries `Msisdn` (full international), `Message`, the `campaign_id` that triggered the send, `UserReference` (the send's id -- the same value the send-log tools call `send_id`), `kind` (`optIn`, `optOut` or `unknown`), `Received` and `updatedAt`. Any field typed `string | string[]` may be given several values, which are OR-ed. Replies can be RECLASSIFIED or hidden after the fact, which is what `updatedAt` moves for. Requires the `reply.read` permission on the API key. MEASURED, AND IT DISAGREES WITH THE DOCUMENTATION. Dripcel's Replies page prints `Permissions: ["replies.read"]` and the hand-built ledger carried that spelling, but the live API answers 403 `Must have the 'reply.read' permission(s)` -- SINGULAR (measured 2026-09-23 with a key holding none of the sixteen). The permission this integration names is the one the server enforces; if Dripcel's key-creation screen offers a checkbox spelt `replies.read`, that is the same permission under the documentation's spelling. Every Dripcel reply is `{ok: true, data}` or `{ok: false, error}`, so a 200 carrying `ok: false` is an application error rather than a success. Dripcel rate-limits to about 50 requests per minute PER ORGANISATION and answers 429 `{ok: false, error: {resetsAt, remaining}}`; that is the organisation's shared budget, never the credential. A 403 names the API-key permission it wanted (`Insufficient permissions. Must have the '<name>' permission(s)`) and means the key was minted without it -- regenerate or modify the key under Profile > API Keys rather than retrying.
dripcel_post_salesWRITEUpload sales via POST /sales. Records conversions against campaigns, in bulk. THE BODY IS A JSON ARRAY, not an object. Each sale needs `campaign_id` and `cell`; `soldAt` defaults to now and `saleValue` to the campaign's `defaultSaleValue`. For a `Campaigns V2` campaign the cell MUST be in international format (South Africa: 27631231234). A campaign Dripcel cannot resolve answers 404, and a sale with the same cell, campaign and `soldAt` date as an existing one answers 409 `"Duplicate sale"` -- which makes the triple the idempotency key. Requires the `sale.create` permission on the API key. Measured 2026-09-23: a key without it answers 403 naming `sale.create`. Every Dripcel reply is `{ok: true, data}` or `{ok: false, error}`, so a 200 carrying `ok: false` is an application error rather than a success. Dripcel rate-limits to about 50 requests per minute PER ORGANISATION and answers 429 `{ok: false, error: {resetsAt, remaining}}`; that is the organisation's shared budget, never the credential. A 403 names the API-key permission it wanted (`Insufficient permissions. Must have the '<name>' permission(s)`) and means the key was minted without it -- regenerate or modify the key under Profile > API Keys rather than retrying.
dripcel_post_send_email_bulkWRITESend a bulk email via POST /send/email/bulk. Sends one email template to many addresses. `from`, `template_id` and `destinations` are required; `template_id` is an `_id` from the email templates tool. `to_start_at` schedules it for later instead of sending immediately. `filter_non_contacts` drops addresses that are not Dripcel contacts, and Dripcel documents it as REQUIRED when the template contains custom fields to substitute. THIS SENDS REAL EMAIL TO EVERY ADDRESS IN `destinations` AND SPENDS CREDITS, and there is no unsend. Unlike the SMS tool it has no test mode, so the only safe rehearsal is a `destinations` list of addresses you own. The success body is an empty object -- it confirms acceptance, not delivery; follow delivery through the send-log and deliveries tools. Requires the `sendLog.create` permission on the API key. Measured 2026-09-23: a key without it answers 403 naming `sendLog.create`. Every Dripcel reply is `{ok: true, data}` or `{ok: false, error}`, so a 200 carrying `ok: false` is an application error rather than a success. Dripcel rate-limits to about 50 requests per minute PER ORGANISATION and answers 429 `{ok: false, error: {resetsAt, remaining}}`; that is the organisation's shared budget, never the credential. A 403 names the API-key permission it wanted (`Insufficient permissions. Must have the '<name>' permission(s)`) and means the key was minted without it -- regenerate or modify the key under Profile > API Keys rather than retrying.
dripcel_post_send_logs_searchREADSearch send logs via POST /send-logs/search. Searches send logs by campaign and by the datetime delivery started. The reply carries `total`, the `send_logs` themselves and the `parsed` search input -- which is what to page with: raise `options.skip` by `options.limit` until `skip` reaches `total`. `options.limit` defaults to about 1000. Requires the `sendLog.read` permission on the API key. Measured 2026-09-23: a key without it answers 403 naming `sendLog.read`. Every Dripcel reply is `{ok: true, data}` or `{ok: false, error}`, so a 200 carrying `ok: false` is an application error rather than a success. Dripcel rate-limits to about 50 requests per minute PER ORGANISATION and answers 429 `{ok: false, error: {resetsAt, remaining}}`; that is the organisation's shared budget, never the credential. A 403 names the API-key permission it wanted (`Insufficient permissions. Must have the '<name>' permission(s)`) and means the key was minted without it -- regenerate or modify the key under Profile > API Keys rather than retrying.
dripcel_post_send_smsWRITESend an SMS via POST /send/sms. Sends one SMS. `content`, `cell`, `skipNonContacts`, `country` and `deliveryMethod` are all required. `campaign_id` attributes the send so hooks can fire on a reply. The reply carries `customerId` -- the id to pass to the deliveries tool to follow this send's delivery status -- and `totalCost`. THIS SENDS A REAL MESSAGE TO A REAL PHONE AND SPENDS CREDITS, and there is no unsend. `sendOptions.testMode: true` is the way to exercise the call without doing that. `skipNonContacts` decides whether a number that is not one of the organisation's contacts is messaged at all, and template substitution in `content` only works for contacts in the organisation. Requires the `sendLog.create` permission on the API key. Measured 2026-09-23: a key without it answers 403 naming `sendLog.create`. Every Dripcel reply is `{ok: true, data}` or `{ok: false, error}`, so a 200 carrying `ok: false` is an application error rather than a success. Dripcel rate-limits to about 50 requests per minute PER ORGANISATION and answers 429 `{ok: false, error: {resetsAt, remaining}}`; that is the organisation's shared budget, never the credential. A 403 names the API-key permission it wanted (`Insufficient permissions. Must have the '<name>' permission(s)`) and means the key was minted without it -- regenerate or modify the key under Profile > API Keys rather than retrying.
dripcel_put_contactsWRITEUpload or update contacts via PUT /contacts. Creates contacts AND updates existing ones, taking the same body and returning the same reply as the create-only upload. Slower and more expensive against the rate limit, capped at 20,000 contacts per request rather than 100,000. Prefer the create-only tool when nothing existing has to change. `send` is the one field to read twice: supplying it TRIGGERS A REAL SEND to the contacts this call uploads, attributed to `campaign_id` and rendered from `template`. That spends credits and messages real people. Omit it unless a send is what you mean. Requires the `contact.update` permission on the API key. Measured 2026-09-23: a key without it answers 403 naming `contact.update`. Note the nesting Dripcel documents -- holding `contact.update` implies `contact.update.tag_ids` and `contact.update.deduped_campaign_ids`, but holding either of those does NOT imply `contact.update`. Every Dripcel reply is `{ok: true, data}` or `{ok: false, error}`, so a 200 carrying `ok: false` is an application error rather than a success. Dripcel rate-limits to about 50 requests per minute PER ORGANISATION and answers 429 `{ok: false, error: {resetsAt, remaining}}`; that is the organisation's shared budget, never the credential. A 403 names the API-key permission it wanted (`Insufficient permissions. Must have the '<name>' permission(s)`) and means the key was minted without it -- regenerate or modify the key under Profile > API Keys rather than retrying.
dripcel_put_contacts_by_cell_optOutWRITEOpt a contact out of one campaign via PUT /contacts/{cell}/optOut. Opts one contact out of exactly one campaign, named by the REQUIRED `campaign_id`. Dripcel's own note prefers the POST tool beside it, which takes a list; this one exists for the single-campaign case. An unparseable number answers 400 `"Invalid cell number"`. Requires the `contact.update.deduped_campaign_ids` permission on the API key. Measured 2026-09-23: a key without it answers 403 naming `contact.update.deduped_campaign_ids`. Every Dripcel reply is `{ok: true, data}` or `{ok: false, error}`, so a 200 carrying `ok: false` is an application error rather than a success. Dripcel rate-limits to about 50 requests per minute PER ORGANISATION and answers 429 `{ok: false, error: {resetsAt, remaining}}`; that is the organisation's shared budget, never the credential. A 403 names the API-key permission it wanted (`Insufficient permissions. Must have the '<name>' permission(s)`) and means the key was minted without it -- regenerate or modify the key under Profile > API Keys rather than retrying.
dripcel_put_contacts_by_cell_tag_addWRITEAdd tags to a contact via PUT /contacts/{cell}/tag/add. Adds tags to one contact, by `tag_ids` (preferred -- ids are stable) or by `tags` names (which change). `create_missing_contact` applies to THIS tool only, not to the remove tool: it creates the contact with these tags when the cell number is not yet a contact. A request carrying no valid tag answers 400 `"No tags to add/remove"`. Requires the `contact.update.tag_ids` permission on the API key. Measured 2026-09-23: a key without it answers 403 naming `contact.update.tag_ids`. Nested under `contact.update`. Every Dripcel reply is `{ok: true, data}` or `{ok: false, error}`, so a 200 carrying `ok: false` is an application error rather than a success. Dripcel rate-limits to about 50 requests per minute PER ORGANISATION and answers 429 `{ok: false, error: {resetsAt, remaining}}`; that is the organisation's shared budget, never the credential. A 403 names the API-key permission it wanted (`Insufficient permissions. Must have the '<name>' permission(s)`) and means the key was minted without it -- regenerate or modify the key under Profile > API Keys rather than retrying.
dripcel_put_contacts_by_cell_tag_removeWRITERemove tags from a contact via PUT /contacts/{cell}/tag/remove. Removes tags from one contact, by `tag_ids` (preferred) or by `tags` names. Takes the same body and returns the same reply as the add tool, except that `create_missing_contact` has no meaning here. A request carrying no valid tag answers 400 `"No tags to add/remove"`. Requires the `contact.update.tag_ids` permission on the API key. Measured 2026-09-23: a key without it answers 403 naming `contact.update.tag_ids`. Every Dripcel reply is `{ok: true, data}` or `{ok: false, error}`, so a 200 carrying `ok: false` is an application error rather than a success. Dripcel rate-limits to about 50 requests per minute PER ORGANISATION and answers 429 `{ok: false, error: {resetsAt, remaining}}`; that is the organisation's shared budget, never the credential. A 403 names the API-key permission it wanted (`Insufficient permissions. Must have the '<name>' permission(s)`) and means the key was minted without it -- regenerate or modify the key under Profile > API Keys rather than retrying.
dripcel_put_exchange_buyer_transaction_by_id_statusWRITEAccept or reject a marketplace transaction via PUT /exchange/buyer/transaction/{id}/status. Settles one PENDING marketplace transaction: `completed` accepts it -- crediting the seller's wallet and debiting your credits -- and `rejected` refuses it, with no wallet movement. The id is the transaction's own, which the search tool returns. An id Dripcel cannot resolve answers 400 `{"code":"transaction_not_found"}` rather than 404. MOVES MONEY on `completed`. If you already know the outcome when the lead is submitted, set `status` on the create tool instead and save the round trip. Dripcel documents no permission for this endpoint, and it is NOT assumed to be open: on 2026-09-23 a key holding NONE of Dripcel's sixteen permissions reached it successfully, which is what an ungated endpoint looks like and what a gated one cannot do. Recorded as measured rather than asserted. Measured here directly: with a valid body and an unknown id, this endpoint reached the transaction LOOKUP -- 400 `transaction_not_found` -- for that same permissionless key, which a permission-gated endpoint could not do. Every Dripcel reply is `{ok: true, data}` or `{ok: false, error}`, so a 200 carrying `ok: false` is an application error rather than a success. Dripcel rate-limits to about 50 requests per minute PER ORGANISATION and answers 429 `{ok: false, error: {resetsAt, remaining}}`; that is the organisation's shared budget, never the credential. A 403 names the API-key permission it wanted (`Insufficient permissions. Must have the '<name>' permission(s)`) and means the key was minted without it -- regenerate or modify the key under Profile > API Keys rather than retrying.
Often connected alongside
Put Dripcel behind one governed endpoint.
Same permissions, same audit trail, whatever else you connect next.