# Kartra > Kartra is an all-in-one online business platform combining landing pages and funnels, email marketing and automation sequences, checkouts and recurring billing, membership sites and courses, video hosting, calendars and booking, helpdesks, affiliate management and lead scoring. Its developer surface is an inbound single-endpoint RPC API, an outbound webhook API, and an IPN payment-notification system. Kartra publishes no OpenAPI, no SDK and no signed webhooks. > > Generated by API Evangelist. Kartra does not publish an llms.txt of its own (https://kartra.com/llms.txt returns 404). This file is assembled from Kartra's public documentation and the artifacts in this profile. ## API surface - [Inbound API](https://support.kartra.com/en/articles/15369010-using-kartra-s-inbound-api-read-me): POST https://app.kartra.com/api, form-encoded, 29 commands selected by `actions[].cmd`. One lead per call. - [Connecting to the API](https://support.kartra.com/en/articles/15369013-connecting-to-the-api): three credentials in the body — `app_id` (developer), `api_key` + `api_password` (end user). HTTPS required. - [Outbound API](https://support.kartra.com/en/articles/15369054-activating-the-outbound-api): 24 JSON webhook events, `{lead, action, action_details}`. - [IPN](https://support.kartra.com/en/articles/15369003-the-ipn-system): 6 payment-lifecycle form POSTs. Empty values arrive as the literal string "N/A". - [API limits](https://support.kartra.com/en/articles/15369015-api-limits): 20 calls/second per App; 429 on exhaustion; no rate-limit headers. - [Success and error messages](https://support.kartra.com/en/articles/15369014-success-and-error-confirmation-messages): everything returns HTTP 200; branch on the numeric `type` in the body. ## Things an agent must know before calling - **HTTP status is not the success signal.** Authentication failure, validation failure and business rejection all return 200. The only documented non-200 is 429. - **A chained call reports per-action results.** Top-level `"status": "Success"` does not mean each entry in `actions[]` succeeded — walk them. - **`create_lead` / `edit_lead` / `search_lead` must be `actions[0]`.** Kartra resolves the subject lead from the first command. - **No idempotency, anywhere.** No key, no dedupe window, no request id. Recover from an uncertain write by re-reading with `get_lead`, never by replaying. - **No pagination.** Account-wide `retrieve_*` commands return everything. - **Unknown custom field identifiers are silently ignored**, not rejected. - **Webhooks are unsigned.** No HMAC, no secret, no timestamp, no replay protection on either callback surface. - **Timestamps are EST with no offset**, format `YYYY-MM-DD HH:MM:SS`. - **Test Mode rewrites lead email domains to @kartra.com** and suppresses all outbound email. ## Specs - No OpenAPI, Swagger, GraphQL, AsyncAPI, JSON Schema or Protobuf is published. Probed 2026-08-12 against kartra.com, app.kartra.com, api.kartra.com and support.kartra.com — all miss. - No `/.well-known/` document is served by Kartra. No agent card at `/.well-known/agent-card.json` or `/.well-known/agent.json`. - No MCP server. ## Artifacts in this profile - [Conventions](conventions/kartra-conventions.yml) — request shape, identity resolution, idempotency, pagination, error envelope, timezone - [Authentication](authentication/kartra-authentication.yml) — the three-credential model and the developer/user role split - [Error codes](errors/kartra-error-codes.yml) — 74 documented error types - [Webhooks and IPN](asyncapi/kartra-webhooks.yml) — 24 outbound events + 6 IPN notifications - [Data model](data-model/kartra-data-model.yml) — 19 entities and their relationships - [Rate limits](rate-limits/kartra-rate-limits.yml) - [Sandbox](sandbox/kartra-sandbox.yml) — Test Mode vs Live Mode - [Lifecycle](lifecycle/kartra-lifecycle.yml) — versioning, status page, deprecation posture - [Changelog](changelog/kartra-changelog.yml) — recent platform releases - [Plans and pricing](plans/kartra-plans-pricing.yml) - [Conformance](conformance/kartra-conformance.yml) — GDPR and PCI DSS claims; standards not met - [Packages](packages/kartra-packages.yml) — no first-party SDK exists - [Agent skills](skills/_index.yml) - [MCP candidate](mcp/kartra-mcp.yml) — derived proposal, not published by Kartra - [Well-known probe](well-known/kartra-well-known.yml) - [Domain security](security/kartra-domain-security.yml) ## Docs - [Developer collection](https://support.kartra.com/en/collections/19655232-developers) — 72 articles - [Help centre](https://support.kartra.com/en/) - [Release notes](https://support.kartra.com/en/collections/19655235-release-notes) - [Integrations and APIs](https://kartra.com/integrations-and-apis/) - [Pricing](https://kartra.com/pricing/) - [Status](https://status.kartra.com/) - [GDPR](https://kartra.com/gdpr/) · [DPA](https://kartra.com/dpa/) · [Terms](https://kartra.com/terms-conditions/) · [Privacy](https://kartra.com/privacy-policy/) ## Known broken entry points Kartra's own [Integrations and APIs](https://kartra.com/integrations-and-apis/) page links developers to `https://documentation.kartra.com/`, which returns **404**. The legacy Freshdesk help centre at `support.kartra.com/support/solutions/*` also 404s. The live developer documentation is at `https://support.kartra.com/en/collections/19655232-developers`.