OneSignal
MARKETING · MARKETING
Push and email messages, apps, users, subscriptions, segments, and journeys in the account they connected.
Acts as the person, not as itself
Each user connects their own account. Every call carries both identities — the agent and the person it is acting for — so the agent can never reach past what that individual can already do.
Credentials never touch the agent
Tokens live in the vault and attach server-side at call time. The agent holds a session, not a secret, and revoking access does not mean rotating a key.
Every call on the record
Who asked, which agent acted, which action ran, and the verdict that let it through — one audit trail across every integration, not one per vendor.
What an agent can do
Each action is granted on its own. An agent allowed to read is not thereby allowed to write, and the scope beside each row is what the acting user must have connected for it to run at all.
onesignal_delete_apps_by_app_id_auth_tokens_by_token_idWRITEDelete an API key via DELETE /apps/{app_id}/auth/tokens/{token_id}. Permanently delete an API key. Any client still authenticating with it starts failing at once. ORGANIZATION KEY: this route is organization-scoped and an App API key cannot reach it. Fill the Organization API key box on this connection (OneSignal dashboard -> Settings -> Organization settings -> Security -> Keys & IDs), which only an organization Admin can mint. DESTRUCTIVE: the resource is removed and there is no undo through this API. Read it first with the matching Get or List tool if you may need what it held.
onesignal_delete_apps_by_app_id_journeys_by_idWRITEDelete a journey via DELETE /apps/{app_id}/journeys/{id}. Permanently delete a journey. Anyone currently inside it stops progressing and its statistics go with it. DESTRUCTIVE: the resource is removed and there is no undo through this API. Read it first with the matching Get or List tool if you may need what it held.
onesignal_delete_apps_by_app_id_segments_by_segment_idWRITEDelete a segment via DELETE /apps/{app_id}/segments/{segment_id}. Permanently delete a segment. Messages and automations that target it by name stop matching anyone. DESTRUCTIVE: the resource is removed and there is no undo through this API. Read it first with the matching Get or List tool if you may need what it held.
onesignal_delete_apps_by_app_id_subscriptions_by_subscription_idWRITEDelete a subscription via DELETE /apps/{app_id}/subscriptions/{subscription_id}. Permanently delete one subscription. That channel stops receiving messages; the user and its other subscriptions remain. IDENTITY VERIFICATION: if this app has OneSignal's Token Identity Verification (beta) switched on, this route stops accepting the App API key and requires an ES256 JWT minted per end user by the customer's own backend -- a short-lived per-user token, not a credential a connection can hold. With the toggle off (its default) the App API key is what it takes. DESTRUCTIVE: the resource is removed and there is no undo through this API. Read it first with the matching Get or List tool if you may need what it held.
onesignal_delete_apps_by_app_id_users_by_by_alias_label_by_alias_idWRITEDelete a user via DELETE /apps/{app_id}/users/by/{alias_label}/{alias_id}. Permanently delete a user and every subscription attached to it. The person stops receiving messages on all channels and their history is gone. DESTRUCTIVE: the resource is removed and there is no undo through this API. Read it first with the matching Get or List tool if you may need what it held.
onesignal_delete_apps_by_app_id_users_by_by_alias_label_by_alias_id_identity_by_alias_label_to_deleteWRITEDelete an alias via DELETE /apps/{app_id}/users/by/{alias_label}/{alias_id}/identity/{alias_label_to_delete}. Remove one alias label from a user. The user itself and its other aliases are untouched, but anything addressing it by the deleted label stops resolving. DESTRUCTIVE: the resource is removed and there is no undo through this API. Read it first with the matching Get or List tool if you may need what it held.
onesignal_delete_notifications_by_message_idWRITECancel a message via DELETE /notifications/{message_id}. Cancel a scheduled message before it is sent. It only works while the message is still pending: once delivery has begun there is nothing to cancel and nothing here can recall what was already sent. `app_id` is REQUIRED and is a query parameter (the ledger records it at `path`, which its own path template contradicts; corrected from the sibling View message operation). DESTRUCTIVE: the resource is removed and there is no undo through this API. Read it first with the matching Get or List tool if you may need what it held.
onesignal_delete_templates_by_template_idWRITEDelete a template via DELETE /templates/{template_id}. Permanently delete a template. Anything still referencing it by `template_id` -- scheduled messages, journeys, automations -- fails at send time rather than falling back. DESTRUCTIVE: the resource is removed and there is no undo through this API. Read it first with the matching Get or List tool if you may need what it held.
onesignal_get_appsREADView apps via GET /apps. List every app in the organization with its App ID, name and per-platform configuration (Apple, Firebase, web push, Huawei, SMS, email). This is how a caller discovers the `app_id` every other tool here needs. ORGANIZATION KEY: this route is organization-scoped and an App API key cannot reach it. Fill the Organization API key box on this connection (OneSignal dashboard -> Settings -> Organization settings -> Security -> Keys & IDs), which only an organization Admin can mint.
onesignal_get_apps_by_app_idREADView an app via GET /apps/{app_id}. Read one app's settings and channel configuration by App ID. The App ID is a public UUID and is explicitly not a secret.
onesignal_get_apps_by_app_id_auth_tokensREADView API keys via GET /apps/{app_id}/auth/tokens. List the app's API keys (Rich Authentication Tokens) with their ids, names, IP allowlists and creation times. The key VALUES are not returned here -- OneSignal shows a value only when it is created or rotated. ORGANIZATION KEY: this route is organization-scoped and an App API key cannot reach it. Fill the Organization API key box on this connection (OneSignal dashboard -> Settings -> Organization settings -> Security -> Keys & IDs), which only an organization Admin can mint.
onesignal_get_apps_by_app_id_email_analytics_delivery_metricsREADView email delivery metrics via GET /apps/{app_id}/email_analytics/delivery_metrics. Read the app's email bounce and spam-complaint rates over the last 24 hours and the last 30 days. These are the two numbers a sending reputation is judged on.
onesignal_get_apps_by_app_id_inboxREADView inbox broadcasts via GET /apps/{app_id}/inbox. List the app's inbox broadcasts. `last_broadcast_id` is the pagination cursor and `limit` caps the page size.
onesignal_get_apps_by_app_id_journeysREADView journeys via GET /apps/{app_id}/journeys. List the app's journeys with their status, schedule and re-entry rules.
onesignal_get_apps_by_app_id_journeys_by_idREADView a journey via GET /apps/{app_id}/journeys/{id}. Read one journey by id, with its full node graph.
onesignal_get_apps_by_app_id_journeys_by_id_statsREADView journey stats via GET /apps/{app_id}/journeys/{id}/stats. Read one journey's performance -- per node, per branch and per message -- over an optional time window.
onesignal_get_apps_by_app_id_outcomesREADView outcomes via GET /apps/{app_id}/outcomes. Read aggregated outcome counts for the app -- clicks, confirmed deliveries, session duration and any custom outcomes -- selected by `outcome_names` and narrowed by time range, platform and attribution model.
onesignal_get_apps_by_app_id_segmentsREADView segments via GET /apps/{app_id}/segments. List the app's segments with their ids, names and current subscription counts. Paged with `limit` and `offset`.
onesignal_get_apps_by_app_id_segments_by_segment_idREADView a segment via GET /apps/{app_id}/segments/{segment_id}. Read one segment by id, with the filters that define it.
onesignal_get_apps_by_app_id_subscriptions_by_subscription_id_user_identityREADView identity by subscription via GET /apps/{app_id}/subscriptions/{subscription_id}/user/identity. Read the alias map of whichever user owns this subscription. The reverse lookup: subscription id in, identity out. IDENTITY VERIFICATION: if this app has OneSignal's Token Identity Verification (beta) switched on, this route stops accepting the App API key and requires an ES256 JWT minted per end user by the customer's own backend -- a short-lived per-user token, not a credential a connection can hold. With the toggle off (its default) the App API key is what it takes.
onesignal_get_apps_by_app_id_users_by_by_alias_label_by_alias_idREADView a user via GET /apps/{app_id}/users/by/{alias_label}/{alias_id}. Read one user, addressed by any alias -- `external_id`, `onesignal_id` or a custom alias label -- with its identity, properties and every subscription attached to it.
onesignal_get_apps_by_app_id_users_by_by_alias_label_by_alias_id_identityREADView a user's aliases via GET /apps/{app_id}/users/by/{alias_label}/{alias_id}/identity. Read the full alias map for one user -- every label and id it can be addressed by, including the `onesignal_id` OneSignal assigned it.
onesignal_get_apps_by_app_id_users_by_by_alias_label_by_alias_id_inboxREADView a user's inbox messages via GET /apps/{app_id}/users/by/{alias_label}/{alias_id}/inbox. List one user's inbox messages with their read, opened and deleted state. OneSignal documents `last_message_id` as the pagination cursor and the ledger records it as REQUIRED, so pass the id you last saw (or the empty string to ask for the first page).
onesignal_get_apps_by_app_id_users_by_by_alias_label_by_alias_id_inbox_unread_countREADView a user's unread inbox count via GET /apps/{app_id}/users/by/{alias_label}/{alias_id}/inbox/unread_count. Return how many inbox messages this user has not read. The number an app badge is drawn from.
onesignal_get_notificationsREADView messages via GET /notifications. List the app's messages, newest first, with their delivery counts. `limit` and `offset` page through them (50 per page by default), `kind` selects dashboard / API / automated messages, `template_id` narrows to one template and `time_offset` shifts the window.
onesignal_get_notifications_by_message_idREADView a message via GET /notifications/{message_id}. Read one message by id with its full delivery breakdown -- successful, failed, errored, converted, remaining -- and optionally its outcome counts via `outcome_names`, `outcome_time_range`, `outcome_platforms` and `outcome_attribution`.
onesignal_get_organizations_by_organization_id_audit_logsREADList audit logs via GET /organizations/{organization_id}/audit_logs. Read the organization's audit log -- who did what and when, ordered by `occurred_at` ascending, filterable by app, action, actor, target, IP and time window. The array filters are capped by OneSignal (10 entries each, 20 for `actions`). ORGANIZATION KEY: this route is organization-scoped and an App API key cannot reach it. Fill the Organization API key box on this connection (OneSignal dashboard -> Settings -> Organization settings -> Security -> Keys & IDs), which only an organization Admin can mint.
onesignal_get_templatesREADView templates via GET /templates. List the app's message templates. `app_id` is required, `channel` narrows to one channel, and `limit`/`offset` page through the results.
onesignal_get_templates_by_template_idREADView a template via GET /templates/{template_id}. Read one template by id, with its contents and settings. `app_id` is required.
onesignal_patch_apps_by_app_id_auth_tokens_by_token_idWRITEUpdate an API key via PATCH /apps/{app_id}/auth/tokens/{token_id}. Rename an API key or change its IP allowlist. The reply is an empty object; re-read with View API keys to see the change. ORGANIZATION KEY: this route is organization-scoped and an App API key cannot reach it. Fill the Organization API key box on this connection (OneSignal dashboard -> Settings -> Organization settings -> Security -> Keys & IDs), which only an organization Admin can mint.
onesignal_patch_apps_by_app_id_journeys_by_idWRITEUpdate a journey via PATCH /apps/{app_id}/journeys/{id}. Update a journey's settings or its node graph. A `nodes` array in the body REPLACES the graph rather than merging into it, so read the journey first and send the whole graph back -- or use Update a journey node to change one node.
onesignal_patch_apps_by_app_id_journeys_by_id_nodes_by_node_idWRITEUpdate a journey node via PATCH /apps/{app_id}/journeys/{id}/nodes/{node_id}. Update a single node inside a journey without resending the whole graph. The narrow edit to prefer over Update a journey.
onesignal_patch_apps_by_app_id_segments_by_segment_idWRITEUpdate a segment via PATCH /apps/{app_id}/segments/{segment_id}. Rename a segment or replace the filters that define it. The filter array REPLACES the segment's definition rather than adding to it, so read the segment first if you mean to extend it.
onesignal_patch_apps_by_app_id_subscriptions_by_subscription_idWRITEUpdate a subscription via PATCH /apps/{app_id}/subscriptions/{subscription_id}. Update one subscription by id: its token, enabled flag, notification types, session data and device metadata. Setting `enabled` to false is how a subscription is suppressed without deleting it. IDENTITY VERIFICATION: if this app has OneSignal's Token Identity Verification (beta) switched on, this route stops accepting the App API key and requires an ES256 JWT minted per end user by the customer's own backend -- a short-lived per-user token, not a credential a connection can hold. With the toggle off (its default) the App API key is what it takes.
onesignal_patch_apps_by_app_id_subscriptions_by_subscription_id_ownerWRITETransfer a subscription via PATCH /apps/{app_id}/subscriptions/{subscription_id}/owner. Move a subscription from its current user to another, named by alias. Used when a device or address changes hands between accounts. IDENTITY VERIFICATION: if this app has OneSignal's Token Identity Verification (beta) switched on, this route stops accepting the App API key and requires an ES256 JWT minted per end user by the customer's own backend -- a short-lived per-user token, not a credential a connection can hold. With the toggle off (its default) the App API key is what it takes.
onesignal_patch_apps_by_app_id_subscriptions_by_subscription_id_user_identityWRITECreate an alias by subscription via PATCH /apps/{app_id}/subscriptions/{subscription_id}/user/identity. Add alias labels to the user that owns this subscription, without having to resolve that user first. IDENTITY VERIFICATION: if this app has OneSignal's Token Identity Verification (beta) switched on, this route stops accepting the App API key and requires an ES256 JWT minted per end user by the customer's own backend -- a short-lived per-user token, not a credential a connection can hold. With the toggle off (its default) the App API key is what it takes.
onesignal_patch_apps_by_app_id_subscriptions_by_token_by_token_type_by_tokenWRITEUpdate a subscription by token via PATCH /apps/{app_id}/subscriptions_by_token/{token_type}/{token}. Update a subscription addressed by its TOKEN rather than its id -- the device push token, email address or phone number, with `token_type` naming which. The route for a caller that holds the token and not the subscription id.
onesignal_patch_apps_by_app_id_users_by_by_alias_label_by_alias_idWRITEUpdate a user via PATCH /apps/{app_id}/users/by/{alias_label}/{alias_id}. Update a user's properties: tags, language, timezone, country, session counts and purchase records. Tags are MERGED, and a tag sent with an empty string value is how one is removed.
onesignal_patch_apps_by_app_id_users_by_by_alias_label_by_alias_id_identityWRITECreate an alias via PATCH /apps/{app_id}/users/by/{alias_label}/{alias_id}/identity. Add one or more alias labels to an existing user, addressed by an alias it already has. Adding an alias that belongs to a different user is refused rather than moving it.
onesignal_patch_apps_by_app_id_users_by_by_alias_label_by_alias_id_inboxWRITEBulk update inbox message state via PATCH /apps/{app_id}/users/by/{alias_label}/{alias_id}/inbox. Mark EVERY matching inbox message for one user read, opened or deleted, up to `last_message_id`. `is_deleted: true` hides all of them from that user's inbox for good, and there is no per-message confirmation in the reply -- it answers 204 with no body.
onesignal_patch_apps_by_app_id_users_by_by_alias_label_by_alias_id_inbox_by_message_idWRITEUpdate an inbox message state via PATCH /apps/{app_id}/users/by/{alias_label}/{alias_id}/inbox/{message_id}. Mark one of a user's inbox messages read, opened or deleted. `is_deleted` hides it from that user's inbox for good; the other two flags are ordinary state. Answers 204 with no body.
onesignal_patch_templates_by_template_idWRITEUpdate a template via PATCH /templates/{template_id}. Update one template's name, contents or channel settings. Messages already scheduled against it pick up the change.
onesignal_post_appsWRITECreate an app via POST /apps. Create a new OneSignal app and set its channel configuration in one call -- APNs key or certificate, Firebase service account, web push keys, Huawei, and the SMS and email sender settings. The response carries the new App ID. ORGANIZATION KEY: this route is organization-scoped and an App API key cannot reach it. Fill the Organization API key box on this connection (OneSignal dashboard -> Settings -> Organization settings -> Security -> Keys & IDs), which only an organization Admin can mint.
onesignal_post_apps_by_app_id_activities_activity_by_activity_typeWRITEStart a Live Activity via POST /apps/{app_id}/activities/activity/{activity_type}. Start an iOS Live Activity of the named type for the targeted subscriptions, with its initial content state. iOS only.
onesignal_post_apps_by_app_id_auth_tokensWRITECreate an API key via POST /apps/{app_id}/auth/tokens. Mint a new API key for the app, optionally restricted to an IP allowlist in CIDR notation. THE RESULT IS REDACTED: the reply carries the new key's value in `formatted_token`, and Agentic Fabriq replaces it before the reply reaches an agent. OneSignal shows that value once and cannot show it again, so mint keys in the dashboard when you need to read one. Note that an IP allowlist will block Agentic Fabriq's own egress unless its addresses are included. ORGANIZATION KEY: this route is organization-scoped and an App API key cannot reach it. Fill the Organization API key box on this connection (OneSignal dashboard -> Settings -> Organization settings -> Security -> Keys & IDs), which only an organization Admin can mint.
onesignal_post_apps_by_app_id_auth_tokens_by_token_id_rotateWRITERotate an API key via POST /apps/{app_id}/auth/tokens/{token_id}/rotate. Issue a new value for an existing API key. THE PREVIOUS VALUE STOPS WORKING IMMEDIATELY, for every client still using it, including this connection if it is the key being rotated -- there is no grace period and no way to recover the old value. THE RESULT IS REDACTED: the reply carries the new value in `formatted_token` and Agentic Fabriq replaces it before the reply reaches an agent, so rotate in the dashboard when you need to read the new value. ORGANIZATION KEY: this route is organization-scoped and an App API key cannot reach it. Fill the Organization API key box on this connection (OneSignal dashboard -> Settings -> Organization settings -> Security -> Keys & IDs), which only an organization Admin can mint. DESTRUCTIVE: the resource is removed and there is no undo through this API. Read it first with the matching Get or List tool if you may need what it held.
onesignal_post_apps_by_app_id_custom_eventsWRITECreate custom events via POST /apps/{app_id}/custom_events. Record up to a megabyte of custom events against users, each naming the user by External ID or OneSignal ID and carrying its own payload. Give each event an `idempotency_key` so a retry cannot double-count it. Partial success is normal: the 202 reply lists the events that failed and the rest were processed.
onesignal_post_apps_by_app_id_inboxWRITECreate an inbox broadcast via POST /apps/{app_id}/inbox. Create an in-app inbox broadcast for the app, with its per-language contents, optional image and custom data. Returns the new broadcast's id.
onesignal_post_apps_by_app_id_journeysWRITECreate a journey via POST /apps/{app_id}/journeys. Create a journey: its audience, trigger, schedule, re-entry rules, early-exit conditions and the whole node graph of messages, waits and branches.
onesignal_post_apps_by_app_id_journeys_by_id_duplicateWRITEDuplicate a journey via POST /apps/{app_id}/journeys/{id}/duplicate. Copy a journey into a new, separate journey, optionally overriding its name and settings. The copy starts paused; nothing is sent by duplicating.
onesignal_post_apps_by_app_id_live_activities_by_activity_id_notificationsWRITEUpdate a Live Activity via POST /apps/{app_id}/live_activities/{activity_id}/notifications. Push a new content state to a running iOS Live Activity, optionally with an alert, and optionally ending it (`event: end`). Ending one cannot be undone from here -- a new activity has to be started.
onesignal_post_apps_by_app_id_notifications_by_notification_id_unsubscribeWRITEUnsubscribe with a token via POST /apps/{app_id}/notifications/{notification_id}/unsubscribe. Unsubscribe the recipient of one message, using the `token` from that message's own unsubscribe link. The token is per message and per recipient and is the argument that identifies them -- there is nothing to look up and no way to guess one.
onesignal_post_apps_by_app_id_segmentsWRITECreate a segment via POST /apps/{app_id}/segments. Create a segment from a named list of filter conditions combined with `AND`/`OR` operators. The reply carries the new segment's id.
onesignal_post_apps_by_app_id_usersWRITECreate a user via POST /apps/{app_id}/users. Create a user with its identity aliases, properties (tags, language, timezone, country) and any subscriptions to attach in the same call. Idempotent on the alias: creating a user whose alias already exists updates that user rather than making a second one. IDENTITY VERIFICATION: if this app has OneSignal's Token Identity Verification (beta) switched on, this route stops accepting the App API key and requires an ES256 JWT minted per end user by the customer's own backend -- a short-lived per-user token, not a credential a connection can hold. With the toggle off (its default) the App API key is what it takes.
onesignal_post_apps_by_app_id_users_by_by_alias_label_by_alias_id_subscriptionsWRITECreate a subscription via POST /apps/{app_id}/users/by/{alias_label}/{alias_id}/subscriptions. Attach a new subscription -- an email address, a phone number or a push token -- to an existing user, addressed by one of its aliases.
onesignal_post_notifications_by_message_id_export_eventsREADExport message events as CSV via POST /notifications/{message_id}/export_events. Generate a CSV of one message's events and return a download URL. The file is produced asynchronously and the URL is valid for three days.
onesignal_post_notifications_by_message_id_historyREADExport message history via POST /notifications/{message_id}/history. Email a CSV of the subscriptions that were SENT or CLICKED one message, to the address in the body. The report is delivered by email rather than returned here, so the reply only confirms the request was accepted. Requires the Email Message Reporting add-on, and `sent` events are not recorded for messages targeting fewer than 1,000 recipients.
onesignal_post_notifications_count_unsavedREADCount message recipients via POST /notifications/count-unsaved. Return how many subscriptions a message's targeting WOULD reach, without creating or sending anything. Takes the same targeting fields as Create message. The safest way to check an audience before sending: it answers `count` plus whether a plan cap reduced it.
onesignal_post_notifications_emailWRITECreate an email message via POST /notifications. Send or schedule an EMAIL message. The same Create message endpoint as the push and SMS tools; `target_channel` defaults to `email` here and `email_subject` plus `email_body` are required. Carries the email-only fields -- from name and address, reply-to, preheader, BCC, click tracking, sender domain and warm-up. THIS SENDS REAL EMAIL and cannot be recalled once delivery starts.
onesignal_post_notifications_pushWRITECreate a push message via POST /notifications. Send or schedule a PUSH message. The channel is chosen by `target_channel` in the body, which defaults to `push` here. Targeting is one of segments (`included_segments`/`excluded_segments`), filters, aliases (`include_aliases`, which requires `target_channel`) or subscription ids; `contents` carries the per-language body and is required. Supports scheduling (`send_after`, `delayed_option`, `delivery_time_of_day`), per-platform assets, action buttons, and `idempotency_key` to make a retry safe. THIS SENDS REAL MESSAGES TO REAL PEOPLE and cannot be recalled once delivery starts.
onesignal_post_notifications_smsWRITECreate an SMS message via POST /notifications. Send or schedule an SMS or MMS message. The same Create message endpoint as the push and email tools, with `target_channel` required and defaulting to `sms`; `sms_from` names the Messaging Service SID or number to send from and `sms_media_urls` attaches MMS media. THIS SENDS REAL, BILLABLE MESSAGES to real phone numbers and cannot be recalled once delivery starts.
onesignal_post_players_csv_exportREADExport subscriptions as CSV via POST /players/csv_export. Generate a CSV of the app's subscription records and return its download URL. `segment_name` limits it to one segment, `extra_fields` adds columns such as external user id, country and timezone, and `last_active_since` limits it by recency. The file is produced asynchronously -- the URL is returned at once and the object may take a few minutes to appear -- and is available for three days.
onesignal_post_templatesWRITECreate a template via POST /templates. Create a reusable message template for a channel, with its per-language contents and channel-specific settings.
onesignal_post_templates_by_template_id_copy_to_appWRITECopy a template to another app via POST /templates/{template_id}/copy_to_app. Copy one template into a different app in the same organization. Two apps are involved, which is why this is the one template tool that needs the Organization API key. ORGANIZATION KEY: this route is organization-scoped and an App API key cannot reach it. Fill the Organization API key box on this connection (OneSignal dashboard -> Settings -> Organization settings -> Security -> Keys & IDs), which only an organization Admin can mint.
onesignal_put_apps_by_app_idWRITEUpdate an app via PUT /apps/{app_id}. Update one app's name and channel configuration. Fields the body omits keep their current values; a field sent empty clears it, which for a platform credential silently stops that channel delivering. ORGANIZATION KEY: this route is organization-scoped and an App API key cannot reach it. Fill the Organization API key box on this connection (OneSignal dashboard -> Settings -> Organization settings -> Security -> Keys & IDs), which only an organization Admin can mint.
Often connected alongside
Put OneSignal behind one governed endpoint.
Same permissions, same audit trail, whatever else you connect next.