# iContact > iContact is an email marketing and marketing automation platform (part of Cision) for small and mid-market businesses. Its public REST API — version 2.2, live at https://app.icontact.com/icp — covers contacts, lists, segments, campaigns, messages, sends, uploads, engagement reporting and webhooks. This file was GENERATED by API Evangelist on 2026-08-13. iContact does not publish an llms.txt: https://www.icontact.com/llms.txt returns 404 and https://help.icontact.com/llms.txt returns 401. iContact's robots.txt additionally carries `User-agent: GPTBot / Disallow: /`. Everything below is transcribed from iContact's own public documentation or observed on a live probe; nothing is inferred. ## What an agent needs to know first - **There is no OpenAPI, Swagger, GraphQL, AsyncAPI or MCP server.** The documentation is prose HTML in a Salesforce Experience Cloud knowledge base. There is nothing to validate a request against. - **Auth is three custom headers**, not OAuth: `API-AppId`, `API-Username`, `API-Password`, plus `API-Version` (2.0, 2.1 or 2.2). No tokens, no scopes, no refresh. - **POST on a member is a merge update; PUT on a member is a destructive replace** that deletes every field you do not send. This inverts standard REST expectations and is the most dangerous convention on this API. - **No sandbox, no dry-run, no idempotency key.** Every call hits production and no write is safe to retry blindly. - **`GET /contacts` silently returns 20 rows and silently omits contacts not on a list.** Pass `limit` and `status=total`. ## Base URLs - Production: `https://app.icontact.com/icp` - Sandbox: none. The legacy host `app.sandbox.icontact.com` fails TLS certificate validation (probed 2026-08-13); iContact's own guide now says to test on a free production account. - Retired: `https://api.icpro.co/icp` (no DNS) and `https://api.omkt.co/icp` (no HTTP response). ## Authentication Send on every request: ``` Accept: application/json Content-Type: application/json API-Version: 2.2 API-AppId: API-Username: API-Password: ``` Credentials are issued at Settings and Billing → iContact Integrations → Custom API Integrations. A third-party app's `API-AppId` must be enabled by the account owner at https://app.icontact.com/icp/core/externallogin. `accountId` and `clientFolderId` scope nearly every URI. Discover them with `GET /a/` then `GET /a/{accountId}/c/`. - Auth reference: https://help.icontact.com/customers/s/article/API-Getting-Started-Guide ## The one unauthenticated endpoint ``` GET https://app.icontact.com/icp/time → {"time":"2026-08-13T13:30:19-04:00","timestamp":1786642219} ``` Verified live 2026-08-13, HTTP 200. Useful as a reachability and clock check. ## Conventions - **Formats:** `application/json` or `text/xml`. 406 on an unsupported Accept, 415 on an unsupported Content-Type. - **Pagination:** `?limit=&offset=`. Default limit **20**. Responses carry sibling `limit`, `offset`, `total`. - **Sorting:** `?orderby=field1:desc,field2`. Ascending by default. - **Filtering:** one query parameter per field; `*` wildcard; comparison via `{field}SearchType` = `eq|gt|gte|lt|lte|bet`. - **Timestamps:** ISO 8601, `YYYY-MM-DD[THH:MM:SS[±HH:MM]]`. Exception: send `scheduledTime` must be exactly `YYYY-MM-DDTHH:MM:SS-04:00` Eastern. - **Field names are case sensitive.** An empty search value returns nothing rather than being ignored. - **Errors:** `{"errors":["prose"],"warnings":["prose"]}`. No RFC 9457, no error code, no field pointer. - **Rate limits:** enforced but entirely unpublished — no number, no window, no header, no documented 429. Reference: https://help.icontact.com/customers/s/article/Advanced-Users-iContact-API ## Resources All paths below are relative to `https://app.icontact.com/icp/a/{accountId}/c/{clientFolderId}` unless noted. ### Audience - `GET|POST /contacts`, `GET|POST|PUT|DELETE /contacts/{contactId}` — https://help.icontact.com/customers/s/article/Contacts-iContact-API - `GET|POST /lists`, `GET|POST|PUT|DELETE /lists/{listId}` — https://help.icontact.com/customers/s/article/Lists-iContact-API - `GET|POST /subscriptions`, `GET|POST|PUT /subscriptions/{listId}_{contactId}` — the join between contacts and lists; creating a contact does NOT subscribe it — https://help.icontact.com/customers/s/article/Subscriptions-iContact-API - `GET|POST /segments`, `GET|POST|DELETE /segments/{segmentId}` — https://help.icontact.com/customers/s/article/Segments-iContact-API - `GET|POST /segments/{segmentId}/criteria` — https://help.icontact.com/customers/s/article/Segment-Criteria-iContact-API - `GET|POST /customfields` — https://help.icontact.com/customers/s/article/Custom-Fields-iContact-API - `GET /contacts/{contactId}/actions` — contact history — https://help.icontact.com/customers/s/article/Contact-History-iContact-API - `GET /signupforms` — read-only; returns a ready-made embed snippet — https://help.icontact.com/customers/s/article/Sign-Up-Forms-iContact-API - `POST /uploads` then `PUT /uploads/{uploadId}/data` — bulk import, `.csv`/`.xls`/`.xlsx` — https://help.icontact.com/customers/s/article/Uploads-iContact-API ### Messaging - `GET|POST /campaigns` — sender identity: fromName, fromEmail, footer address, click tracking — https://help.icontact.com/customers/s/article/Campaigns-iContact-API - `GET|POST /messages` — requires `campaignId`, `messageType`, `subject`. Cannot be deleted via the API — https://help.icontact.com/customers/s/article/Messages-iContact-API - `GET|POST /sends` — **dispatches real email.** Requires `messageId` and `includeListIds` (unless segment-only) — https://help.icontact.com/customers/s/article/Sends-iContact-API - `POST /automations/{automationType}` — create-only; cannot be read, updated or deleted — https://help.icontact.com/customers/s/article/Automations-iContact-API ### Engagement (poll-only) - `GET /messages/{messageId}/statistics` — bounces, delivered, unsubscribes, opens{unique,total}, clicks{unique,total}, forwards, comments, complaints - `GET /messages/{messageId}/opens` · `/clicks` · `/bounces` · `/unsubscribes` ### Account - `GET /a/` · `GET /a/{accountId}/c/` · `GET /a/{accountId}/c/{clientFolderId}` - `GET|POST|DELETE /a/{accountId}/users/{userId}` · `GET|POST /a/{accountId}/users/{userId}/permissions` ## Webhooks `GET|POST /webhooks`, `GET|DELETE /webhooks/{webhookId}`. JSON callbacks only. Four events: `contact_created`, `contact_updated`, `contact_subscribed`, `contact_unsubscribed`. No signature, no retry policy, no delivery guarantee is documented. iContact states explicitly that "Do Not Contact" events **cannot** be monitored. There are no send, delivery, bounce, open or click events — all message engagement is poll-only. Reference: https://help.icontact.com/customers/s/article/Web-Hooks-iContact-API ## HTTP status codes 200 OK · 400 Bad Request · 401 Not Authorized · 402 Payment Required (unpaid bill) · 403 Forbidden · 404 Not Found · 405 Method Not Allowed · 406 Not Acceptable · 415 Unsupported Media Type · 500 Internal Server Error · 501 Not Implemented (often a bad `API-Version`) · 503 Service Unavailable · 507 Insufficient Space (plan storage exhausted). Reference: https://help.icontact.com/customers/s/article/HTTP-Status-Codes-iContact-API ## Client libraries Three first-party PHP libraries on GitHub, none published to any package registry, none tagged or released, newest commit 2018-03-12: - https://github.com/icontact/icontact-api-php — targets the live API. Note it sets `CURLOPT_SSL_VERIFYPEER = false`. - https://github.com/icontact/icontact-pro-api-php — targets api.icpro.co, which no longer resolves. - https://github.com/icontact/icontact-pro-select-api-php — targets api.omkt.co, which no longer answers. There is no first-party JavaScript, Python, Ruby, Java, Go, .NET or CLI client, and no Postman collection. Every registry-installable iContact client is third-party. ## Plans Standard / Premium / Ultimate, priced by contact-list size across nine tiers from 500 to 50,000 contacts ($9–$427/month), plus a quoted enterprise tier above that. 30-day free trial, no credit card. API access is not gated by plan on the published comparison, and there is no API metering or per-call price. https://www.icontact.com/pricing/ ## Operations - Status page: https://status.icontact.com/ — publishes an "API System" component. RSS incident history at https://status.icontact.com/history.rss. No JSON status endpoint. - No changelog. The Advanced Users article lists "API Version Changelog" in its own table of contents but publishes no such section. - No deprecation policy, no Sunset/Deprecation headers, no SLA. - No `/.well-known/` documents on any host. No security.txt, no bug bounty, no trust centre, no named certifications. ## Links - Developer portal: https://help.icontact.com/customers/s/article/API-Developer-Portal - Getting started: https://help.icontact.com/customers/s/article/API-Getting-Started-Guide - Full resource reference: https://help.icontact.com/customers/s/article/Resource-Call-References-List-iContact-API - Code library: https://help.icontact.com/customers/s/article/Code-Library-iContact-API - Glossary: https://help.icontact.com/customers/s/article/Developer-Glossary-iContact-API - Website: https://www.icontact.com - Help portal: https://help.icontact.com/customers/s/ - GitHub: https://github.com/icontact - Pricing: https://www.icontact.com/pricing/ - Terms: https://www.icontact.com/legal/terms-conditions/ - Privacy: https://www.icontact.com/legal/privacy/ - Anti-spam / CASL: https://www.icontact.com/legal/anti-spam-policy/