# Oracle Responsys > Oracle Responsys (Responsys Campaign Management) is a B2C cross-channel marketing > orchestration platform — email, mobile push, SMS, MMS, web push and display — that > unifies customer data into targeted audiences and delivers personalized messages in near > real-time. Originally Responsys, acquired by Oracle in 2014 and now part of Oracle > Marketing. It exposes a REST API (v1.3), an asynchronous (AFTM) API, an Event > Notification webhook API, and a legacy SOAP API. > > Generated by API Evangelist from the Responsys developer documentation and the harvested > Swagger 2.0. Oracle publishes no llms.txt of its own (probed docs.oracle.com and > www.oracle.com, 2026-08-13 — 404). ## APIs - [Oracle Responsys REST API (v1.3)](https://docs.oracle.com/en/cloud/saas/marketing/responsys-rest-api/index.html): 88 operations over profile lists, recipients, profile extension and supplemental tables, campaigns, schedules, programs, folders, content library, triggered email/SMS/push, events and account settings. - [Responsys Event Notification API](https://docs.oracle.com/en/cloud/saas/marketing/responsys-develop/API/REST/EventNotification/rest-event-notifications.htm): webhook callbacks for 26 campaign event types. Controlled Availability. - [Responsys AFTM / Asynchronous API](https://docs.oracle.com/en/cloud/saas/marketing/responsys-develop/API/GetStarted/Overview/rest-aftm.htm): queued high-availability variants of merge and trigger. Controlled Availability. - [Responsys SOAP API (legacy)](https://docs.oracle.com/en/cloud/saas/marketing/responsys-soap-api/index.html): Controlled Availability, existing customers only. ## Specs - [Swagger 2.0 for the REST API](https://docs.oracle.com/en/cloud/saas/marketing/responsys-rest-api/swagger.json): info.version 2023.03.03, 63 paths, 88 operations, 100 definitions. Declares no host, no basePath, no securityDefinitions, and only a `default` response per operation. - No OpenAPI 3.x. No AsyncAPI. No GraphQL. No gRPC. ## Docs - [API hub / getting started](https://docs.oracle.com/en/cloud/saas/marketing/responsys-develop/API/api.htm) - [Developer's Guide](https://docs.oracle.com/en/cloud/saas/marketing/responsys-develop/index.html) - [REST endpoint reference](https://docs.oracle.com/en/cloud/saas/marketing/responsys-rest-api/rest-endpoints.html) - [Authentication endpoint URLs](https://docs.oracle.com/en/cloud/saas/marketing/responsys-develop/API/GetStarted/Authentication/auth-endpoints-rest.htm) - [Throttling limits](https://docs.oracle.com/en/cloud/saas/marketing/responsys-rest-api/Throttling.html) - [Changes and enhancements by release](https://docs.oracle.com/en/cloud/saas/marketing/responsys-rest-api/releaseChanges.html) - [APIs and SDKs — availability and entitlement](https://docs.oracle.com/en/cloud/saas/marketing/responsys-user/API.htm) - [Mobile App Platform SDK docs](https://docs.oracle.com/en/cloud/saas/marketing/responsys-develop-mobile/) ## Authentication - Two-hop session token. `POST /rest/api/v1.3/auth/token` against a login host returns an `authToken` and an `endPoint`; use `endPoint` as the base URL for everything after, and send `Authorization: ` with no scheme prefix. - `auth_type` is one of `password`, `token` (refresh), `certificate`. - Login hosts: login2.responsys.net, login5.responsys.net, login.rsys8.net, login.rsys9.net, or `{accountToken}-api.responsys.ocs.oraclecloud.com` for global routing. - Not OAuth 2.0. No scopes. No OIDC. ## Runtime semantics an agent needs - **Rate limits** are per API function, per account, per minute. Default 200/min for high-volume functions; Login 10, Merge List Recipients 1000, Retrieve List Recipients 100. Read the account's real ceilings from `GET /rest/api/ratelimit` — note the path is UNVERSIONED; adding `v1.3` returns 404. - **No rate-limit response headers.** No `X-RateLimit-*`, no `RateLimit-*`, no `Retry-After`. On exhaustion the body carries `errorCode: API_LIMIT_EXCEEDED`. - **No idempotency.** No idempotency key, no dedupe header. Treat every triggered send as at-most-once; do not auto-retry on timeout. - **Error envelope** is `{type, title, errorCode, detail, errorDetails[]}` — shaped like RFC 9457 but not it. `type` is an empty string in every published example. Branch on `errorCode`. - **Addressing is by name**, not id — `listName`, `campaignName`, `programName`, `folderName`, `petName`, `tableName`. Renaming an object in the UI changes its API address. The one opaque id is RIID. - **POST is overloaded** on `/lists/{listName}/members` and the PET members path: merge, retrieve-multiple and delete-multiple share one path+method and are selected by request body. - **API hosts are not publicly reachable.** TCP 443 to login2/login5.responsys.net times out from the open internet; access is from provisioned customer networks. ## Key resources - Profile Lists: `/rest/api/v1.3/lists`, `/lists/{listName}/fields` - Recipients: `/lists/{listName}/members`, `/lists/{listName}/members/{riid}`, `/members/count` - Profile Extension Tables: `/lists/{listName}/listExtensions/{petName}/members` - Supplemental Tables: `/suppData`, `/folders/{folderName}/suppData/{tableName}/members` - Campaigns: `/campaigns`, `/campaigns/actions/search`, `/campaigns/{campaignName}/preview` - Schedules: `/campaigns/{campaignName}/schedule`, `/schedule/{scheduleId}` - Triggered messages: `/campaigns/{campaignName}/email`, `/sms/trigger`, `/push`, `/emailAttachments/actions/trigger` - Programs: `/programs`, `/programs/{programName}`, `/programs/enactments` - Events: `/events`, `/events/{eventName}`, `/events/rei/{eventName}` - Content Library: `/clDocs`, `/clFolders`, `/clItems`, `/clDocImages/{documentPath}` - Account: `/user/info`, `/settings/account`, `/settings/account/domains/email` - Event notifications: `/notifications/eventList`, `/notifications/callbacks`, `/notifications/subscriptions` ## Event types (webhooks) EMAIL_BOUNCED, EMAIL_FAILED, EMAIL_SKIPPED, EMAIL_CLICKED, EMAIL_OPTOUT, EMAIL_OPTIN, EMAIL_COMPLAINT, SMS_FAILED, SMS_SKIPPED, SMS_MO_FW_FAILED, SMS_RECEIPT, SMS_OPT_IN, SMS_OPT_OUT, MMS_SKIPPED, MMS_FAILED, PUSH_SKIPPED, PUSH_FAILED, PUSH_BOUNCED, PUSH_OPT_IN, PUSH_OPT_OUT, WEBPUSH_FAILED, WEBPUSH_SKIPPED, WEBPUSH_BOUNCED, WEBPUSH_CLOSED, WEBPUSH_OPTIN, WEBPUSH_OPTOUT. There is no EMAIL_SENT and no EMAIL_OPENED. ## SDKs - No first-party client library exists for the REST API in any language. - First-party packages are all mobile push SDKs: `@oracle/react-native-pushiomanager` (npm), `oracle-samples/pushiomanager-flutter`, `oracle/pushiomanager-cordova-plugin`, and the PushIOManager Android `.aar` / iOS `.xcframework` downloaded from oracle.com. - The two Python "Responsys" packages on PyPI are community projects, last released 2019 and 2015. ## Commercial - No published pricing. Enterprise contact-sales only. - Standard REST and SOAP are complimentary with a subscription. Advanced, Asynchronous, Asynchronous Reporting, Events and AFTM are Controlled Availability via a My Oracle Support service request; Events and AFTM additionally require a separate SKU. - Vulnerability disclosure: secalert_us@oracle.com (Oracle corporate). No bug bounty; researcher credit in the quarterly Critical Patch Update.