# Sailthru > Cross-channel relationship-marketing and personalization platform for media, publishing, retail and e-commerce brands — email, SMS, mobile push, in-app and on-site messaging around a single customer profile. Founded 2008, acquired by CM Group/Marigold in 2018, and part of Zeta Global since November 2025. Its public HTTPS API at api.sailthru.com is an RPC-over-HTTP surface authenticated with an api_key plus an MD5 signature over the request parameters. Generated by API Evangelist from the public Sailthru/Zeta developer documentation on 2026-08-12. Sailthru does not publish an llms.txt of its own; the llms.txt served at zetaglobal.com is the parent company's corporate marketing document and does not describe this API. ## What an agent needs to know first - Base URL: `https://api.sailthru.com/` — GET, POST or DELETE. There is no version segment; the API is unversioned. - Every request carries three signed parameters: `api_key`, `sig` (MD5 of secret + api_key + format + the alphabetically sorted parameter values), and `format` (`json` or `xml`). Do not URL-encode parameters before computing the signature — only after. - Serialization is chosen by the signed `format` parameter, not by an `Accept` header. - POST bodies are `application/x-www-form-urlencoded`. Complex arguments are JSON-encoded *inside* form parameters; there is no JSON request body. - Errors return `{error: , errormsg: }`. This is not RFC 9457 Problem Details. - There is no idempotency key. Retrying a POST /send after a timeout can duplicate a message. - Rate limits are returned as `X-Rate-Limit-Limit`, `X-Rate-Limit-Remaining`, `X-Rate-Limit-Reset`; exhaustion is HTTP 429 with API error 43. - HTTPS and UTF-8 are required; TLS 1.2 or higher, SSL is not supported. ## APIs - [Sailthru API](https://products.zetaglobal.com/sailthru/Content/developers/api-basics/introduction.html): the core HTTPS API — users, lists, content, templates, blasts, sends, triggers, purchases, events, includes, ad plans, previews, settings, stats and bulk jobs. - [Sailthru JavaScript API (Personalization Engine)](https://products.zetaglobal.com/sailthru/Content/developers/api-client/javascript.html): the browser tag at `https://ak.sail-horizon.com/spm/spm.v1.min.js` for identity capture, commerce tracking, custom events and consent. ## Endpoint reference - [send](https://products.zetaglobal.com/sailthru/Content/developers/api/send.html) — transactional, on-demand messages to individual users - [blast](https://products.zetaglobal.com/sailthru/Content/developers/api/blast.html) — bulk campaigns to a list with a template - [blast-repeat](https://products.zetaglobal.com/sailthru/Content/developers/api/blast-repeat.html) — recurring campaigns - [user](https://products.zetaglobal.com/sailthru/Content/developers/api/user.html) — user profiles, list memberships and custom vars - [list](https://products.zetaglobal.com/sailthru/Content/developers/api/list.html) — list creation, membership and query-backed lists - [content](https://products.zetaglobal.com/sailthru/Content/developers/api/content.html) — the content library used for personalization - [template](https://products.zetaglobal.com/sailthru/Content/developers/api/template.html) — email templates - [trigger](https://products.zetaglobal.com/sailthru/Content/developers/api/trigger.html) — event/trigger pairs that drive transactional sends - [event](https://products.zetaglobal.com/sailthru/Content/developers/api/event.html) — custom events - [purchase](https://products.zetaglobal.com/sailthru/Content/developers/api/purchase.html) — commerce transactions and cart state - [include](https://products.zetaglobal.com/sailthru/Content/developers/api/include.html) — reusable template includes - [ad-plan](https://products.zetaglobal.com/sailthru/Content/developers/api/ad-plan.html) — ad plans - [preview](https://products.zetaglobal.com/sailthru/Content/developers/api/preview.html) — send a preview of a message - [settings](https://products.zetaglobal.com/sailthru/Content/developers/api/settings.html) — account settings - [stats](https://products.zetaglobal.com/sailthru/Content/developers/api/stats.html) — send, blast and list statistics - [job (update)](https://products.zetaglobal.com/sailthru/Content/developers/api/job-update.html) — asynchronous bulk profile updates - [job (content)](https://products.zetaglobal.com/sailthru/Content/developers/api/job-content.html) — asynchronous bulk content updates - [job (queries)](https://products.zetaglobal.com/sailthru/Content/developers/api/job-queries.html) — asynchronous exports ## Docs - [For Developers Overview](https://products.zetaglobal.com/sailthru/Content/developers/overview.html) - [Introduction to the API](https://products.zetaglobal.com/sailthru/Content/developers/api-basics/introduction.html) - [API Technical Details](https://products.zetaglobal.com/sailthru/Content/developers/api-basics/technical.html) — auth, signature, formats, rate limits - [API Error and Response Codes](https://products.zetaglobal.com/sailthru/Content/developers/api-basics/responses.html) - [API Postbacks](https://products.zetaglobal.com/sailthru/Content/developers/api-basics/postbacks.html) — the webhook surface - [Client Libraries](https://products.zetaglobal.com/sailthru/Content/developers/api-client/libraries-overview.html) - [Zephyr template language](https://products.zetaglobal.com/sailthru/Content/developers/zephyr-syntax/syntax-overview.html) - [Release notes (2026)](https://products.zetaglobal.com/sailthru/Content/ReleaseNotes/releasenotes-2026.htm) ## SDKs - [Node.js — sailthru-client](https://www.npmjs.com/package/sailthru-client) (5.0.5, 2025-02-27) - [.NET — Sailthru.Client](https://www.nuget.org/packages/Sailthru.Client) (1.2.3, 2026-08-12) - [Java — com.sailthru.client:sailthru-java-client](https://central.sonatype.com/artifact/com.sailthru.client/sailthru-java-client) (2.4.1, 2024-02-25) - [Ruby — sailthru-client](https://rubygems.org/gems/sailthru-client) (4.3.0, 2020-07-15) - [Python — sailthru-client](https://pypi.org/project/sailthru-client/) (2.3.5, 2018-07-26) - [PHP — sailthru/sailthru-php5-client](https://packagist.org/packages/sailthru/sailthru-php5-client) (1.2.4, 2017-08-02) - [Perl — Sailthru-Client](https://metacpan.org/dist/Sailthru-Client) (v2.1.0, 2016-05-05) - [GitHub organization](https://github.com/sailthru) ## Events (API postbacks) Sailthru POSTs to a URL you host when one of four events occurs, signed with `api_key` + `sig`: `verify` (double opt-in confirmed), `optout` (opt-out or opt-in), `update` (profile/subscription change on a hosted page), `hardbounce` (permanent delivery failure). Reply 200 on success, 403 or 500 on failure; response codes appear in the account audit log. ## What Sailthru does NOT publish Recorded so an agent does not go looking. No OpenAPI, AsyncAPI, GraphQL, gRPC or MCP server. No `/.well-known/` documents of any kind — no security.txt, no OIDC or OAuth metadata, no api-catalog, no A2A agent card. No OAuth 2.0 and therefore no scopes. No idempotency contract. No public pricing (enterprise contract only). No deprecation policy or Sunset header support. The Atlassian status page at sailthru.statuspage.io has been deactivated and status.sailthru.com returns 403, so there is no readable status page. ## Company and security - [Sailthru product page (Zeta Global)](https://zetaglobal.com/sailthru/) - [Zeta Global Trust Center — Sailthru](https://trust.zetaglobal.com/?product=sailthru) — SOC 2 Type 2 (Align Assurance), ISO/IEC 27001 / 27018 / 27701 (BSI), HITRUST, GDPR, CCPA; reports gated behind an access request - [Vulnerability disclosure (Bugcrowd)](https://bugcrowd.com/engagements/cheetah-vdp) - [Services agreement](https://zetaglobal.com/former-marigold-now-zeta-services-agreement/) · [Privacy policy](https://zetaglobal.com/privacy-policy)