# Campaign Monitor > Campaign Monitor (a Marigold brand) is an email marketing platform. Its REST API — branded "createsend" after the original product name — manages clients, subscriber lists, subscribers, custom fields, segments, campaigns, templates, automated journeys, sending domains and transactional email, and reports on every send. The API is at v3.3 and lives at https://api.createsend.com/api/v3.3/. > Provenance: Campaign Monitor publishes no llms.txt (https://www.campaignmonitor.com/llms.txt returned 404 on 2026-08-13) and no OpenAPI. This file was GENERATED by API Evangelist from the provider's own public documentation and from the artifacts in this repository. Every URL below was fetched. ## Getting started - [API home](https://www.campaignmonitor.com/api/): entry point for all API documentation; states the current version (3.3) and the TLS 1.2 minimum. - [Getting started](https://www.campaignmonitor.com/api/v3-3/getting-started/): authentication, input/output formats, response status codes, rate limiting. - [What's new in v3.3](https://www.campaignmonitor.com/api/v3-3/whats-new/): the 3.2 -> 3.3 change list, including the breaking ones. - [v3.2 archive](https://www.campaignmonitor.com/api/v3-2/): previous-version reference, still published. ## Authentication Two models, both documented on the Getting Started page. - OAuth 2.0 (preferred for third-party integrations). Authorize at https://api.createsend.com/oauth, exchange at https://api.createsend.com/oauth/token, pass the token as `Authorization: Bearer {token}`. Scopes ("permissions") are comma-separated: ViewReports, ManageLists, CreateCampaigns, ImportSubscribers, SendCampaigns, ViewSubscribersInReports, ManageTemplates, AdministerPersons, AdministerAccount, ViewTransactional, SendTransactional, Automation. - API key over HTTP Basic. The key is the username; the password is unused. Keys are account-wide or client-specific. There is no OpenID Connect discovery document and no `/.well-known/oauth-authorization-server` — endpoints must be taken from the docs. ## Request and response conventions - Format is chosen by route extension: `/clients.json` or `/clients.xml`. **XML is the default** if you specify neither; send `Accept: application/json` or use the `.json` suffix. All `/transactional` endpoints are JSON only. - Pagination is page-number based: `page`, `pagesize` (10-1000), `orderfield`, `orderdirection`. Responses carry PageNumber, PageSize, RecordsOnThisPage, TotalNumberOfRecords, NumberOfPages. - `pretty=true` on any request returns indented output. - Errors are a proprietary envelope, not RFC 9457: `{"Code": , "Message": ""}`. The numeric code is the stable identifier; HTTP status is coarse, and a resource ID you do not own returns **401**, not 403 or 404. - **There is no idempotency mechanism.** No Idempotency-Key header, no replay protection, including on the send endpoints. Retries after a timeout must be reconciled by reading state back. - Rate limiting applies to `/transactional` endpoints only, signalled by `X-RateLimit-Limit`, `X-RateLimit-Remaining` and `X-RateLimit-Reset`, with HTTP 429 on exhaustion. ## API surface (v3.3) - [Account](https://www.campaignmonitor.com/api/v3-3/account/): clients, billing details, countries, timezones, system date, administrators, primary contact, embedded session. - [Clients](https://www.campaignmonitor.com/api/v3-3/clients/): create/read/delete clients, lists, segments, suppression list, templates, billing settings, credit transfer, people, tags, sent/scheduled/draft campaigns, sending domains. - [Campaigns](https://www.campaignmonitor.com/api/v3-3/campaigns/): create drafts (from content or a template), send, schedule/unschedule, send previews, and the reporting family — recipients, opens, clicks, bounces, unsubscribes, spam complaints, email client usage, summary. - [Lists](https://www.campaignmonitor.com/api/v3-3/lists/): create/update/delete lists, stats, custom fields and their options, segments, webhooks, and the five subscriber states (active, unconfirmed, unsubscribed, bounced, deleted). - [Subscribers](https://www.campaignmonitor.com/api/v3-3/subscribers/): add, update, import up to 1000 at a time, get details and history, unsubscribe, delete. A subscriber is scoped to a list and addressed by email address — there is no global subscriber ID. - [Segments](https://www.campaignmonitor.com/api/v3-3/segments/): create/update segments, add rule groups, list active subscribers. Engagement segments are system-provided and Premier-plan only. - [Templates](https://www.campaignmonitor.com/api/v3-3/templates/): create, update, copy, delete; strict template-markup validation with its own error class. - [Journeys](https://www.campaignmonitor.com/api/v3-3/journeys/): list journeys, journey summary, per-email reporting, copy a journey, and trigger Subscriber Activity Journeys via `POST /events/publish/{clientId}`. - [Transactional](https://www.campaignmonitor.com/api/v3-3/transactional/): smart email listing and details, send smart email, send classic email, classic email groups, statistics, message timeline, message details, resend. JSON only, rate limited, max 25 recipients per send, 100 KB Data field limit. - [Webhooks](https://www.campaignmonitor.com/api/v3-3/webhooks/): per-list callbacks for Subscribe, Update and Deactivate. Events are batched up to 1000 per POST. **Payloads are unsigned** — there is no signature header. ## Official client libraries All seven are published under https://github.com/campaignmonitor. - Ruby — `createsend` 6.1.2 (2025-06-17), https://rubygems.org/gems/createsend - Python — `createsend` 9.1.4 (2025-06-16), https://pypi.org/project/createsend/ - PHP — `campaignmonitor/createsend-php` v7.1.1 (2025-06-18), https://packagist.org/packages/campaignmonitor/createsend-php - .NET — `campaignmonitor-api` 6.0.2 (2025-03-12), https://www.nuget.org/packages/campaignmonitor-api - Perl — `Net::CampaignMonitor` v2.2.2 (2025-07-02), https://metacpan.org/dist/Net-CampaignMonitor - Java — `com.createsend:createsend-java` 7.0.1 (2022-12-07) — stale, predates v3.3 - Objective-C — `CreateSend` 1.1.1 — unmaintained since 2021 There is no official JavaScript/Node, Go or Rust client. ## Operations, security and commerce - Status page: https://status.campaignmonitor.com/ (shared Marigold status page) - Trust center: https://trust.campaignmonitor.meetmarigold.com/ — SOC 2, GDPR - Vulnerability disclosure: https://www.campaignmonitor.com/.well-known/security.txt (Bugcrowd; note the Expires field has passed) - Report a vulnerability: https://www.campaignmonitor.com/trust/report-a-vulnerability/ - Policies (terms, privacy, acceptable use, anti-spam): https://www.campaignmonitor.com/policies/ - Pricing: https://www.campaignmonitor.com/pricing/ — Lite, Essentials, Premier, Enterprise, priced by contact count - Help center: https://help.campaignmonitor.com/ - Blog: https://www.campaignmonitor.com/blog/ - Integrations: https://www.campaignmonitor.com/integrations/ ## What is not published Recorded so an agent does not go looking: - No OpenAPI or Swagger document (probed `/openapi.json`, `/swagger.json`, `/api-docs`, `/docs` on both api.createsend.com and www.campaignmonitor.com — all 404). - No AsyncAPI document; the event surface is the webhook catalog above. - No GraphQL endpoint. - No MCP server, hosted or local. `mcp.campaignmonitor.com` and `mcp.createsend.com` are wildcard DNS catch-alls that redirect to the website and the app login. - No A2A agent card at `/.well-known/agent-card.json` or `/.well-known/agent.json`. - No `/.well-known/api-catalog`, no OpenID configuration, no OAuth authorization-server metadata. - No dated API changelog and no deprecation policy or Sunset/Deprecation headers. - No sandbox or test-mode credentials; no first-party CLI.