The Server API is called by an app backend. First read the Integration guide for common requests and error handling, then complete Authentication and signing. In-container web apps must also follow Passwordless sign-in to exchange an authorization code for the current user's identity.
Integration and authentication
| Documentation | Entry point | Description |
|---|
| Integration guide | https://{gateway_host} | Unified responses, common request rules, errors, and retries |
| Authentication and signing | /auth/v1/oauth/token | Obtain an app access_token and understand Webhook signing rules |
| Passwordless sign-in | SDK obtains code, /auth/v1/oauth/userinfo | Exchange a page authorization code for the user's identity |
API list
Calling conventions
- All examples use
https://{gateway_host}, app_xxx, and access-token-xxx as placeholders.
- Query and sending APIs include Shell, PHP, Golang, and C++ examples; example secrets must remain on the server.
- Member IDs and department IDs are strings. See the Integration guide for unified responses and error handling.
- Robot write APIs should include
Idempotency-Key; keep the same idempotency key and request body when retrying.