# Playable > Playable (formerly Leadfamly; Playable ApS, Aarhus DK and London UK) is a marketing gamification > platform for building, publishing and measuring interactive campaigns — spin-the-wheel, advent > calendars, quizzes, scratch cards, memory and skill games — across web, email, in-app, in-store and > retail-media placements. Programmatic access is a public REST API at api.playable.com, described by > an OpenAPI 3.0 definition and secured with OAuth 2.0 client-credentials over 37 fine-grained scopes. > API access is a Premium-plan entitlement. Generated by API Evangelist from the published Playable surface. Playable does not serve an llms.txt of its own: https://playable.com/llms.txt returns 404 and https://app.playable.com/llms.txt returns the application's HTML shell, not a document. ## APIs - [Playable API](https://api.playable.com/): REST API for campaign types, campaign lifecycle, sections and form fields, prizes, bulk prizes, vouchers, registrations, email and SMS logs, statistics, game settings, media upload and login tokens. Base URL https://api.playable.com, all resources under /v1/. - [Playable MCP Server](https://playable.com/wp-json/mcp/mcp-oauth-server): hosted Model Context Protocol endpoint on the web property, discovered via RFC 9728 protected-resource metadata. OAuth 2.0 authorization-code + PKCE, scope `mcp`. tools/list is auth-gated (401 anonymous). - [Playable Campaign SDK](https://sdk.playable.com/guide/introduction.html): browser JavaScript SDK exposing window.sdk plus a campaign event stream. ## Specs - [OpenAPI 3.0.0](https://api.playable.com/openapi.yaml): 36 paths, 41 operations, tags oauth/campaigns/media/user. Served from the API host root. - [OAuth authorization server metadata](https://playable.com/.well-known/oauth-authorization-server): RFC 8414. - [OAuth protected resource metadata](https://playable.com/.well-known/oauth-protected-resource): RFC 9728. ## Auth - Token endpoint: POST https://api.playable.com/oauth/token (OAuth 2.0 client_credentials). - Header: `Authorization: Bearer {{ACCESS_TOKEN}}`, plus `Accept: application/json` (the only supported response type). - Credentials are created inside the platform under Global settings / Developer apps. - 37 scopes, one per capability, e.g. campaigns.list, campaigns.view, campaigns.modify, campaigns.registrations.list, campaigns.voucher.delete, media.upload, user.create-login-token. ## Limits - 3,600 requests per hour per developer app. Hard limit; spreading traffic across multiple apps to evade it is prohibited. - Headers: `X-RateLimit-Limit` and `X-RateLimit-Remaining` on every response; `Retry-After` once the limit is hit. - The status code returned on exhaustion is not published, and no 429 is declared in the spec. - Playable explicitly expects clients to cache and to request data only when needed. ## Conventions - Pagination: `?page=N`, with a `data` envelope plus `links` {first,last,prev,next} and `meta` {current_page,from,path,per_page,to}. No total count is returned. - Filtering: `filter_name`, `filter_type`, `filter_template`, `filter_display`. Sorting: `sort=name,created_on` with asc/desc. - Expansion: `with=` a comma-separated list (registrations, sessions, integrations, sections, sections.form_fields, bulk_prizes, ...). - Errors: `{"message": "..."}`. Not RFC 9457. No machine-readable error code. - No idempotency key. No Sunset/Deprecation header. No documented request-id correlation header. ## Docs - [API reference (Swagger UI)](https://api.playable.com/) - [Developer settings / developer apps](https://help.playable.com/en/articles/10384051-developer) - [Help center](https://help.playable.com/en/) - [Webhook integration](https://help.playable.com/en/articles/5807069-webhook-integration) - [Integration status codes](https://help.playable.com/en/articles/6969461-api-integration-logs-and-status-codes) - [SDK documentation](https://sdk.playable.com/) - [Pricing](https://playable.com/pricing/) - [Status page](https://status.playable.com/) - [SLA](https://playable.com/playable-sla/) - [ISO 27001 / GDPR / security](https://playable.com/iso-gdpr-security/) ## Events - No AsyncAPI document is published. The event surface is a per-campaign outbound webhook, configured in the campaign builder, POSTing form-encoded or JSON with OAuth 2.0, bearer or basic auth. Payload fields are mapped by the operator; there is no fixed payload schema, no signature header and no published retry policy. ## Not published - No /.well-known/security.txt, no vulnerability disclosure program, no bug bounty. - No A2A agent card at /.well-known/agent-card.json or /.well-known/agent.json on any host. - No dated changelog or release notes. - No CLI, no server-side SDK; the only first-party package is @playable-marketing/campaign-sdk (npm, 0.2.0, last published 2024-09-25) which wraps the browser surface, not the REST API.