# Push (PUSHTech / Cendyn CRM) > Hospitality CRM and customer data platform for hotels — unifies the guest database and > orchestrates pre-stay, during-stay and post-stay communication across email, SMS and web/app > push. Originally PUSHTech, now Cendyn CRM following acquisition by Cendyn. Exposes a > token-authenticated REST API of 67 operations across 15 resources, an HMAC-signed webhook > surface with five event groups, and a first-party JavaScript Web SDK for browser tracking and > web push. This file is GENERATED by API Evangelist from the artifacts in the api-evangelist/push repo. Cendyn CRM does not publish an llms.txt of its own (probed 2026-08-13: developers.cendyncrm.com answers /llms.txt with a 200 HTML error shell, api.eu/api.us return 404). ## Getting started - [Developer portal](https://developers.cendyncrm.com/): Cendyn CRM Developers Central. - [API overview](https://developers.cendyncrm.com/api): what the REST API is for. - [Authentication](https://developers.cendyncrm.com/api/authentication): `Authorization: Token token={account_secret}`. Not Bearer. No OAuth, no scopes. - [API reference](https://developers.cendyncrm.com/api/reference): all 67 operations, with a data-center selector. - [Webhooks](https://developers.cendyncrm.com/api/webhooks): event groups, payload fields, HMAC verification, retry schedule. - [Web SDK](https://developers.cendyncrm.com/websdk): browser tracking and web push. ## Base URLs The account lives in exactly one data center. The two are NOT interchangeable — calling the wrong one returns 401 with the same message as an invalid token. - EU: `https://api.eu.cendyncrm.com` - US: `https://api.us.cendyncrm.com` ## Specs and artifacts - [OpenAPI 3.1 (derived)](https://raw.githubusercontent.com/api-evangelist/push/refs/heads/main/openapi/push-cendyn-crm-openapi.yml): 67 operations, 41 paths, 15 tags. DERIVED by API Evangelist from the provider's HTML reference — Cendyn CRM publishes no OpenAPI. - [AsyncAPI 3.0 (derived)](https://raw.githubusercontent.com/api-evangelist/push/refs/heads/main/asyncapi/push-webhooks-asyncapi.yml): five webhook channels with payload schemas. DERIVED — Cendyn CRM publishes no AsyncAPI. - [Webhook catalog](https://raw.githubusercontent.com/api-evangelist/push/refs/heads/main/asyncapi/push-webhooks.yml) - [Authentication profile](https://raw.githubusercontent.com/api-evangelist/push/refs/heads/main/authentication/push-authentication.yml) - [API conventions](https://raw.githubusercontent.com/api-evangelist/push/refs/heads/main/conventions/push-conventions.yml) - [Error catalog](https://raw.githubusercontent.com/api-evangelist/push/refs/heads/main/errors/push-problem-types.yml) - [Data model](https://raw.githubusercontent.com/api-evangelist/push/refs/heads/main/data-model/push-data-model.yml) - [Lifecycle](https://raw.githubusercontent.com/api-evangelist/push/refs/heads/main/lifecycle/push-lifecycle.yml) - [Conformance](https://raw.githubusercontent.com/api-evangelist/push/refs/heads/main/conformance/push-conformance.yml) - [Packages / SDK](https://raw.githubusercontent.com/api-evangelist/push/refs/heads/main/packages/push-packages.yml) - [Agent skills](https://raw.githubusercontent.com/api-evangelist/push/refs/heads/main/skills/_index.yml) ## Resources Every path is account-scoped: `/v2/account/{account_id}/{resource}`. - **Account** — read the prepaid credit balance (`currentBalanceAccount`). - **Contact** — the root entity. Create, bulk create, show, update, list, delete, email validation. - **Company** — B2B accounts, with their own custom fields. - **Product** — catalog, keyed by UUID. - **Purchase** — purchase history attached to a contact; the CDP fact table. - **Coupon lists** — create, list, redeem. - **Hotel Data** — the hospitality-specific entity, with per-language content. - **Audience List** — segmentation containers. - **Campaigns** — READ ONLY over the API. Authored in the manager UI; the API can list, show and preview a per-contact message but cannot create or send a campaign. - **Deliveries** — send email, SMS or push; show and list delivery status. - **Sync Data** — bulk composite ingest of contacts and purchases. The ONLY resource published without a `/v2` prefix. - **Custom fields** — separate CRUD resources for contact, company, product and hotel data. ## What an agent needs to know before calling this API - **No idempotency.** No `Idempotency-Key` header and no retry contract on any of the 67 operations. A retried `createContact` duplicates the guest; a retried delivery send messages the guest twice and charges the account twice. - **No pagination.** No page, cursor, offset or limit parameter on any list operation. You cannot tell whether a list response is complete. - **No rate limits published**, and no `X-RateLimit-*`, `RateLimit-*` or `Retry-After` header on live responses. - **Errors are a bare string**: `{"error": ""}`. No code, no field pointer, not RFC 9457. - **`x-request-id` is returned on every response** but is undocumented. Log it. - **Deliveries and email validation consume a prepaid balance.** Check `currentBalanceAccount` first; the behaviour at zero is undocumented. - **The delivery status enum contains `deliverd`** — the provider's own misspelling — and `undefined` as a real value. Match on what is published, not what is correct. - **No app resource.** Push sends require an `app_id` that exists only in the manager UI. - **No MCP server, no agent card, no `/.well-known/` document of any kind** (all probed 2026-08-13). ## Events (webhooks) Registered by hand in the manager UI — there is no subscription API. - `activities` — contact interactions and behaviours (14 types, from `open_app` to `gps_location`). - `deliveries` — message status across sms, push, email. **Never retried on subscriber failure.** - `contacts` — create, channel_subscription, update, destroy. Updates carry only changed keys plus a `contact_url` to fetch the full record. - `bulk_contacts` — async result of a batch import, with valid/failed counts. - `incoming_sms` — inbound text messages. Verification: HMAC-SHA256 over `concat(timestamp, token)` keyed with the account secret, hex-encoded, compared to the `Authorization` header. The signature does NOT cover the event body. ## Commercial - No public pricing. Sales-gated — "Request Demo" / "Contact" only. - Prepaid consumption balance for deliveries and email validation; no published rate card. - [Terms of Use](https://www.cendyn.com/terms-of-use/) · [Privacy Policy](https://www.cendyn.com/privacy-policy/) ## Notes on this profile - The developer portal moved from `developers.pushtech.com` to `developers.cendyncrm.com` with no redirect; the old hostnames no longer resolve. The API host's own 404 body is the only breadcrumb to the new location. - The Web SDK's newest build is version 2.9.0, last modified 2024-06-26, and still carries the retired PUSHTech brand in its class name and CDN hostname. - No status page, no changelog, no SLA, no deprecation policy.