Skip to main content
POST
Error

Autorizações

Authorization
string
header
obrigatório

A staff session token, uk_st_…. Minted by sign-up, sign-in or the two-factor exchange. Only a 401 means it is spent; not_a_member (403) is about the organization named in X-Organization-Id and leaves the token good for the others.

Cabeçalhos

X-Organization-Id
string

The organization the caller is acting on — the org_… code that appears in the panel URL. It identifies; the membership JOIN is what authorizes, so a forged code reads nothing: the answer is not_a_member (403), which does not mean the session is over. Absent, the session's default organization answers, or — if that membership was revoked while the session was open — any other one the caller still holds.

Parâmetros de caminho

id
string<uuid>
obrigatório

Parâmetros de consulta

environment
enum<string>
padrão:live

Which environment to act in. A view parameter, valid only on the staff surface — a machine credential never chooses its environment, it is resolved from the key.

Opções disponíveis:
live,
test

Corpo

application/json
body_text
string
obrigatório
visibility
enum<string>
padrão:public
Opções disponíveis:
public,
internal

Resposta

The message.

One line of a conversation. An internal note is a message — same thread, same ordering — and visibility is what keeps it off every contact-facing read.

id
string<uuid>
author_kind
enum<string>
Opções disponíveis:
contact,
agent,
ai,
system
author_user_id
string<uuid> | null

Which staff member, when author_kind is agent.

visibility
enum<string>
Opções disponíveis:
public,
internal
body_text
string
body_html
string | null
created_at
string<date-time>