# Keap > Keap (formerly Infusionsoft, now a Thryv company) is a CRM, sales and marketing > automation platform for small businesses. Its public API covers contacts, companies, > opportunities, orders, subscriptions, products, discounts, affiliates, tasks, notes, > files, tags, campaigns and automations across two REST versions plus a deprecated > XML-RPC surface, and a live OAuth-gated remote MCP server. Generated by API Evangelist from Keap's own published contracts and documentation on 2026-08-13. Keap does not publish an llms.txt; this file is generated, not harvested. ## Contracts - [Keap REST v2 OpenAPI 3.1](https://crm.infusionsoft.com/app/v3/api-docs/V2): 237 paths, 399 operations, 384 schemas. The Default version. - [Keap REST v1 OpenAPI 3.1](https://crm.infusionsoft.com/app/v3/api-docs/V1): 92 paths, 141 operations, 210 schemas. Status "Current"; still the only home of REST Hooks, Appointments and Account Info. - [SDK source spec](https://github.com/infusionsoft/keap-sdk/blob/main/sdks/v2/swagger.yml): the same v2 contract, with servers[] naming https://api.keap.com/crm. ## Base URLs - REST v2: `https://api.infusionsoft.com/crm/rest/v2` (also reachable as `https://api.keap.com/crm/rest/v2`) - REST v1: `https://api.infusionsoft.com/crm/rest/v1` - XML-RPC (deprecated): `https://api.infusionsoft.com/crm/xmlrpc` - MCP: `https://api.keap.com/mcp` ## Authentication - [OAuth2 getting started](https://developer.infusionsoft.com/getting-started-oauth-keys/): authorization code + refresh token grants. - [OAuth2 reference](https://developer.infusionsoft.com/authentication/): authorize at `https://accounts.infusionsoft.com/app/oauth/authorize`, token at `https://api.infusionsoft.com/token`. - [Personal Access Tokens and Service Account Keys](https://developer.infusionsoft.com/pat-and-sak/): single-app bearer keys; PAT acts as the creating user, SAK has admin scope. - Only one OAuth scope exists: `full`. - Refresh tokens ROTATE — every refresh returns a new refresh token that must be persisted. ## Rate limits - [Throttles and quotas](https://developer.infusionsoft.com/api-token-quota-and-usage-measurements/) - OAuth key/secret pair: 1,500/minute, 150,000/day (resets 00:00 UTC). - PAT/SAK: 10/second, 240/minute, 30,000/day. - Per application instance (tenant, effective 2026-06-08): 10,000/minute, 250,000/day. - Unmetered spike policy: 25 calls/second. - Read `x-keap-tenant-throttle-available` and `x-keap-product-quota-available` on every response. - Exhaustion returns 429. NOTE: 429 is not declared in the OpenAPI. ## Conventions - Pagination (v2): `page_size` + `page_token`, response `next_page_token`. v1 uses `limit`/`offset`. - Filtering: `filter` query parameter with `==` (prefix wildcards allowed) and `>`/`<`/`>=`/`<=`. - Sorting: `order_by`. Sparse responses: `fields`. - Partial update: `update_mask` query parameter on PATCH (Google AIP-134 field mask). - Custom fields: discover with `GET /rest/v2/{resource}/model`. - Errors: `{code, message, status, details[]}` as `application/json` — NOT RFC 9457 problem+json. - IDEMPOTENCY: not supported. There is no idempotency key on any of the 540 operations, so retrying a POST can duplicate records. ## Events - [REST Hooks documentation](https://developer.infusionsoft.com/rest-hook-documentation/): subscribe via `POST /rest/v1/hooks`, complete the `X-Hook-Secret` handshake, receive batched deliveries of up to 1,000 objects. - Retry policy: four attempts (30–60s, 30–60s, 5min, 30min). A `410` response deactivates the subscription immediately. - Event keys use `noun.verb` syntax; the authoritative list is `GET /rest/v1/hooks/event_keys`. ## SDKs All generated in lock-step at 2.0.20, published 2026-08-13: - [JavaScript](https://www.npmjs.com/package/keap-core-service-v2-sdk-js) - [TypeScript](https://www.npmjs.com/package/keap-core-service-v2-sdk-ts) - [Python](https://pypi.org/project/keap-core-v2-sdk/) - [PHP](https://packagist.org/packages/keap/keap-sdk) - [C#](https://www.nuget.org/packages/Thryv.Keap.Core.V2) - [Java](https://github.com/infusionsoft/keap-sdk/tree/main/sdks/v2/java) — source only, NOT on Maven Central. ## Documentation - [Developer portal](https://developer.keap.com/) - [Developer guide](https://developer.infusionsoft.com/developer-guide/) - [REST v2 reference](https://developer.infusionsoft.com/docs/restv2/) - [REST v1 reference](https://developer.infusionsoft.com/docs/rest/) - [Postman collection](https://documenter.getpostman.com/view/2915979/UVByKWEZ) - [Sandbox application](https://developer.infusionsoft.com/resources/sandbox-application/) - [Payments web component](https://developer.infusionsoft.com/payments-api-integration-configuration/) - [Get support](https://developer.infusionsoft.com/get-support/) / [Community forum](https://community.keap.com/c/api/5) - [Status](https://status.thryv.com/) (Keap is a listed component) ## Optional - [Legacy key deprecation](https://developer.infusionsoft.com/legacy-key-deprecation/) - [Legacy key migration](https://developer.infusionsoft.com/legacy-key-migration/) - [XML-RPC reference (deprecated)](https://developer.infusionsoft.com/docs/xml-rpc/) - [Table schema (XML-RPC)](https://developer.infusionsoft.com/docs/table-schema/) - [Usage guidelines](https://developer.infusionsoft.com/docs/usage-guidelines/) - [Known issues](https://developer.infusionsoft.com/support/known-issues/) - [Pricing](https://keap.com/pricing)