# Listrak > Listrak is a retail customer-engagement platform. Its public API surface is eight separate REST > APIs served from api.listrak.com, covering email, SMS/MMS/RCS, mobile app push, cross-channel > custom events, retail data import, media library management, two-way SMS conversations, and > GDPR/CCPA data deletion. Every server-side API authenticates with OAuth 2.0 client_credentials > against a single token endpoint. Listrak publishes no pricing, no SDK for any server language, no > MCP server, no A2A agent card, no AsyncAPI, and no /.well-known documents. This file was GENERATED by API Evangelist from Listrak's own published specifications and documentation on 2026-08-13. Listrak does not publish an llms.txt of its own (https://www.listrak.com/llms.txt returns 404). ## Authentication - [Token endpoint](https://auth.listrak.com/OAuth2/Token): OAuth 2.0 client_credentials. POST `grant_type=client_credentials`, `client_id`, `client_secret` as `application/x-www-form-urlencoded`. Send the result as `Authorization: Bearer `. - Credentials are issued per Integration inside the Listrak application (Integrations → Integration Management). The client secret is shown once and cannot be recovered. - API access can be paused per Integration; while paused, requests AND token issuance are rejected. - The Mobile App Push client API is the exception — it uses an `x-api-key` header. ## APIs - [Email REST API](https://api.listrak.com/email): 83 operations. Contacts, lists, messages, campaigns, content, split tests, imports, transactional sends, and reporting. Spec: https://api.listrak.com/email/swagger/docs/v1 (Swagger 2.0) - [SMS REST API](https://api.listrak.com/sms): 20 operations. Sender codes, phone lists, subscribers, subscriptions, broadcasts, transactional SMS. Spec: https://api.listrak.com/sms/swagger/docs/v1 (Swagger 2.0) - [Data Import REST API](https://api.listrak.com/data): 5 operations. Bulk upsert of customers, orders, products, reviews and rating summaries, keyed on merchant identifiers. Spec: https://api.listrak.com/data/swagger/docs/v1 (Swagger 2.0) - [Privacy REST API](https://api.listrak.com/privacy): 2 operations. Submit and poll GDPR/CCPA forget requests. The only Listrak API with a published rate limit. Spec: https://api.listrak.com/privacy/swagger/docs/v1 (Swagger 2.0) - [Cross Channel REST API](https://api.listrak.com/crosschannel/v1/docs): 3 operations. Declare-then-post custom events that drive Journey Hub automations; event schemas are retrievable at runtime. Spec: https://api.listrak.com/crosschannel/v1/openapi.json (OpenAPI 3.0.4) - [Two-Way SMS Conversation API](https://api.listrak.com/twowaysms/docs): 4 operations. Support tickets and message streams over SMS. Carries Listrak's only outbound webhook. Spec: https://api.listrak.com/twowaysms/openapi.json (OpenAPI 3.0.1) - [Mobile App Push API](https://api.listrak.com/mobileclient/docs): 5 operations. Device registration and engagement events. Uses an `x-api-key` header. Spec: https://api.listrak.com/mobileclient/openapi.json (OpenAPI 3.0.1) - [Media REST API](https://api.listrak.com/media): 9 operations. Media library directories, image files and fonts. The newest and cleanest of the eight. Spec: https://api.listrak.com/media/openapi/v1.json (OpenAPI 3.1.1) ## Conventions - Versioning is in the URI path; every API is at `v1`. Listrak publishes an explicit breaking-change contract: new required fields or behavior changes bump the version; new fields, new routes and new response headers do not. - Responses are always wrapped. `Collection[T]` / `CollectionPaged[T]` / `Resource[T]` / `ResourceCreated` / `ResourceUpdated` / `ResourceDeleted`, each repeating the HTTP status in the body. A created resource's id comes back as `resourceId`, not in a `Location` header. - Pagination is cursor-based: request `cursor` (default `Start`) and `count` (default 1000, max 5000); follow `nextPageCursor`. The Media API is the exception — page-number pagination with a `totalCount`. - Errors are a flat vendor envelope `{status, error, message}` on `application/json`, NOT RFC 9457 problem+json. `error` is a stable SCREAMING_SNAKE code from a published 68-code registry — branch on it, never on `message`. - **There is no idempotency key.** No Listrak API documents an idempotency header or a retry-dedup contract. A retried send is a second message. The Data Import operations are re-runnable only because they upsert on merchant-owned keys. - Rate limits: only the Privacy API publishes numbers (20 requests / 10 seconds, 60 requests / minute). Mobile App Push and Two-Way SMS declare `429` without a number. No API returns any rate-limit response header and none returns `Retry-After`. - `Content-Type: application/json` is enforced on request bodies; HTTPS is required. ## Events - Outbound: one webhook, on the Two-Way SMS API, fired when an invalid MO is received or an MO arrives for an open ticket. Configured in the UI only; no signing secret, retry policy or management API is documented. - Inbound: Cross Channel custom events (declare a configuration, fetch its schema, post events). - There is NO webhook for email or SMS engagement (opens, clicks, bounces, unsubscribes). Those must be polled from the reporting operations. ## Specs and artifacts - [OpenAPI + Swagger, verbatim](https://github.com/api-evangelist/listrak/tree/main/openapi/_original) - [Refined per-resource OpenAPI](https://github.com/api-evangelist/listrak/tree/main/openapi) - [Authentication profile](https://github.com/api-evangelist/listrak/blob/main/authentication/listrak-authentication.yml) - [OAuth scopes](https://github.com/api-evangelist/listrak/blob/main/scopes/listrak-scopes.yml) - [Error code registry](https://github.com/api-evangelist/listrak/blob/main/errors/listrak-error-codes.yml) - [API conventions](https://github.com/api-evangelist/listrak/blob/main/conventions/listrak-conventions.yml) - [Data model](https://github.com/api-evangelist/listrak/blob/main/data-model/listrak-data-model.yml) - [Rate limits](https://github.com/api-evangelist/listrak/blob/main/rate-limits/listrak-rate-limits.yml) - [Lifecycle](https://github.com/api-evangelist/listrak/blob/main/lifecycle/listrak-lifecycle.yml) - [Webhooks](https://github.com/api-evangelist/listrak/blob/main/asyncapi/listrak-webhooks.yml) - [Agent skills](https://github.com/api-evangelist/listrak/blob/main/skills/_index.yml) - [Packages / SDKs](https://github.com/api-evangelist/listrak/blob/main/packages/listrak-packages.yml) - [Conformance](https://github.com/api-evangelist/listrak/blob/main/conformance/listrak-conformance.yml) ## Docs and operations - [Developer page](https://www.listrak.com/learn/developers) - [Help center](https://help.listrak.com/en/) - [Product updates (the closest thing to a changelog)](https://help.listrak.com/en/collections/3229482-product-updates) - [Status page](https://status.listrak.com) - [Security policy](https://www.listrak.com/privacy-and-terms/security-policy) - [Vulnerability disclosure](https://www.listrak.com/privacy-and-terms/responsible-disclosure) — security@listrak.com - [Privacy policy](https://www.listrak.com/privacy-and-terms/privacy-policy) - API feedback: restapifeedback@listrak.com ## Not available - No MCP server (first-party or community). - No A2A agent card — `/.well-known/agent-card.json` and `/.well-known/agent.json` 404 on every host. - No `/.well-known/` document of any kind, including security.txt and OAuth server metadata. - No AsyncAPI document. - No server-side SDK in any language. The only first-party client code is a pair of mobile App Push SDKs on GitHub, both at 1.0.0 and untouched since February 2021. - No CLI, no sandbox or test-mode credentials, no published pricing.