# CRM Bonus (CRMBonus) > Brazilian retail technology platform for customer acquisition, conversion and > loyalty. Products: Giftback (cashback and rewards), Vale Bonus (a consumer > rewards app reaching over five million shoppers), CRMBack (WhatsApp e-commerce > conversion), CRMAds (retail media on WhatsApp), Conversational Commerce, and > Oto CRM (physical-retail CRM, acquired outright from WPP in June 2025). > Integrates with 300+ ERP, POS and e-commerce systems including VTEX, Shopify, > Linx, TOTVS, Nuvemshop, Wake and PagSeguro. Generated by API Evangelist — CRM Bonus does not publish an llms.txt on any of its hosts (probed 2026-08-12; 404 on crmbonus.com.br, otocrm.com.br, ajuda.otocrm.com.br and data-api.otocrm.com.br). ## What is publicly callable The one publicly documented machine-readable contract is the **Oto Data API** — an OpenAPI 3.1.0 ingestion API for the Oto CRM platform. Thirteen POST operations load customers, orders, order items, products, stores, sellers, cashback credits, NPS responses, an exclusion list, and Oto Tags web events. There is no read side: no GET operation exists on the public surface. Access is by request — a bearer token is issued by Oto/CRMBonus support; there is no self-service key page and no published pricing. The Giftback, Vale Bonus and CRMAds APIs on api.crmbonus.com are partner-token gated with no public reference. That host answers HTTP 200 with an identical `{"correlation_id":"…","message":"OK!!"}` envelope for every path, so a 200 there is not evidence that anything exists at the path requested. ## APIs - [Oto Data API](https://data-api.otocrm.com.br/redoc): REST upsert-ingestion API for the Oto CRM platform. Base URL https://data-api.otocrm.com.br - [Oto Data API — Swagger UI](https://data-api.otocrm.com.br/docs): interactive reference; every operation requires a bearer token - [Oto Data API — staging](https://data-api-hmg.otocrm.com.br): homologação environment, serves the identical spec, writes do not persist, separate credential required ## Specs - [OpenAPI 3.1.0 (JSON, as published)](https://data-api.otocrm.com.br/openapi.json) - openapi/_original/crm-bonus-oto-data-api-openapi.json — harvested verbatim - openapi/crm-bonus-oto-data-api-openapi.yml — YAML rendering - overlays/crm-bonus-oto-data-api-overlay.yaml — API Evangelist enhancements ## How to call it - Auth: `Authorization: Bearer `. Missing credential returns **403** `{"detail":"Not authenticated"}` — not 401. - Every operation takes the same envelope: `{"data": [ … ]}`. - Writes are **upserts** — a record whose primary key exists is replaced in full, so an identical replay is safe; a partial replay erases omitted fields. - Limits: **200 requests/minute per source IP** (throttled, then 429) and **10,000 records per request** (413 over). No `RateLimit-*` or `Retry-After` header is returned. - Errors are `application/json` `{"detail": …}` — FastAPI style, not RFC 9457. A 422 returns `detail[].loc = ["body", , ""]`. ## Docs - [Ingestão de dados via API](https://ajuda.otocrm.com.br/support/solutions/articles/150000032248-ingest%C3%A3o-de-dados-via-api) - [Cadastro rápido via API](https://ajuda.otocrm.com.br/support/solutions/articles/150000031734-cadastro-r%C3%A1pido-via-api) - [Vtex — integração de e-commerce](https://ajuda.otocrm.com.br/support/solutions/articles/150000031710-vtex-integrac%C3%A3o-de-e-commerce) - [Oto CRM help center](https://ajuda.otocrm.com.br/support/solutions) - [Oto CRM status](https://status.otocrm.com.br) — separate components for API Pública, API Privada, Integração de Dados, Plataforma and Oto Tags ## Company - [CRMBonus](https://crmbonus.com.br) / [English](https://www.crmbonus.com.br/en) - [Oto CRM](https://www.otocrm.com.br) - [Blog](https://crmbonus.com.br/blog) - [Support](https://crmbonus.com.br/suporte) - [GitHub](https://github.com/crmbonus-oficial) - [Privacy policy](https://crmbonus.com.br/politicas/politica-de-privacidade) - [Privacy notice and terms of use](https://www.crmbonus.com.br/politicas/aviso-de-privacidade-e-termos-de-uso) - [Data security](https://www.crmbonus.com.br/politicas/seguranca-de-dados) ## Known gaps (probed, not assumed) - No `/.well-known/*` document on any host — no security.txt, no OIDC or OAuth discovery, no api-catalog, no agent card. - No MCP server, no A2A agent card, no GraphQL, no AsyncAPI, no webhooks. - No client SDK for the Oto Data API in any package registry. - No changelog, no deprecation policy, no SLA, no published pricing. - No named security certification (SOC 2, ISO 27001, PCI DSS) is claimed; the published posture is LGPD compliance with a DPO contact and a DSAR portal.