# SendOwl > SendOwl is a UK-based digital commerce platform for selling digital products, subscriptions, > memberships, license keys, drip-delivered courses and physical goods, with hosted checkout and > automated file delivery. It exposes a public REST API at `https://api.sendowl.com/api/v1` covering > products, bundles (packages), subscriptions, drip items, orders, discounts and licenses, in JSON or > XML, authenticated with HTTP Basic (API key + secret), plus an HMAC-SHA256-signed outbound webhook > surface and a browser-side `sendowl.js` checkout/cart library. Generated by API Evangelist from the SendOwl public developer surface on 2026-08-12. SendOwl does not publish an `llms.txt` of its own (`https://www.sendowl.com/llms.txt` and `https://dashboard.sendowl.com/llms.txt` both return 404), so this file is generated, not harvested. ## Before you call anything - Base URL: `https://api.sendowl.com/api/v1` — but the version prefix is **per resource**: discounts live at `/api/v1_2/`, orders at `/api/v1_3/`, everything else at `/api/v1/`. - Auth: HTTP Basic. Username = API key, password = API secret, created at `https://dashboard.sendowl.com/settings/api_credentials`. The API is **off by default** on an account and must be enabled in Settings first. - `Accept: application/json` is **mandatory**. Omitting it returns HTTP 415, not JSON. `Content-Type` is also required on create/update. - Rate limit: about **one request per second**; exceeding it can get your IP blocked. No `RateLimit-*` headers are returned, and no 429 is documented. - There is **no idempotency key** on any write, including `POST /api/v1/orders/{id}/refund`. Do not blind-retry money-moving calls. - Errors are not RFC 9457. A 422 returns `[["field","message"], ...]` in JSON — free text, no codes. - There is no sandbox host. Testing is a Stripe test-mode toggle on the account or on an individual product; the same credentials and the same base URL serve live and test. ## APIs - [SendOwl API](https://dashboard.sendowl.com/developers/api/introduction): REST API for products, bundles, subscriptions, drip items, orders, discounts and licenses. JSON and XML. ## API reference - [Introduction — auth, calls, errors, pagination, call rate](https://dashboard.sendowl.com/developers/api/introduction) - [Products](https://dashboard.sendowl.com/developers/api/products) - [Bundles (packages)](https://dashboard.sendowl.com/developers/api/bundles) - [Subscriptions](https://dashboard.sendowl.com/developers/api/subscriptions) - [Drip items](https://dashboard.sendowl.com/developers/api/drip_items) - [Orders](https://dashboard.sendowl.com/developers/api/orders) - [Discounts and discount codes](https://dashboard.sendowl.com/developers/api/discounts) - [Licenses](https://dashboard.sendowl.com/developers/api/licenses) - [sendowl.js browser library](https://dashboard.sendowl.com/developers/api/sendowl-js) ## Docs - [Developer portal](https://dashboard.sendowl.com/developers) - [Developer overview and custom integrations](https://help.sendowl.com/help/developer-overview-custom-integrations) - [Enabling and using the SendOwl API](https://help.sendowl.com/help/using-the-api) - [Using webhooks](https://help.sendowl.com/help/using-web-hooks) - [Swapping between Stripe live and test modes](https://help.sendowl.com/help/swap-between-live-and-test) - [Placing test orders](https://help.sendowl.com/help/how-to-run-test-orders-in-sendowl) - [Help center](https://help.sendowl.com/help) - [Status page](https://sendowl.status.io/) - [Pricing](https://www.sendowl.com/pricing) - [GitHub organization](https://github.com/SendOwl) ## Events Fourteen webhook events, configured at `https://dashboard.sendowl.com/settings/web_hooks`, signed with the `X-SENDOWL-HMAC-SHA256` header (base64 HMAC-SHA256 of the raw JSON body, keyed with the account Signing Key Secret), retried up to 10 times with exponential backoff on any non-2XX/3XX response: Fraud review · Free order issued · In dispute · New payment · Order charged back · Order completed · Order failed · Order imported · Refund issued · Subscription active · Subscription cancelled · Subscription cancelling · Subscription complete · Subscription setup Pull-based alternative: `GET /api/v1_3/orders?updated_after={ISO 8601 datetime}`. ## API Evangelist artifacts Repo-relative, in `https://github.com/api-evangelist/sendowl`: - [apis.yml](apis.yml) — the APIs.json profile - [authentication/sendowl-authentication.yml](authentication/sendowl-authentication.yml) - [conventions/sendowl-conventions.yml](conventions/sendowl-conventions.yml) - [errors/sendowl-problem-types.yml](errors/sendowl-problem-types.yml) - [rate-limits/sendowl-rate-limits.yml](rate-limits/sendowl-rate-limits.yml) - [plans/sendowl-plans-pricing.yml](plans/sendowl-plans-pricing.yml) - [lifecycle/sendowl-lifecycle.yml](lifecycle/sendowl-lifecycle.yml) - [conformance/sendowl-conformance.yml](conformance/sendowl-conformance.yml) - [data-model/sendowl-data-model.yml](data-model/sendowl-data-model.yml) - [asyncapi/sendowl-webhooks.yml](asyncapi/sendowl-webhooks.yml) - [sandbox/sendowl-sandbox.yml](sandbox/sendowl-sandbox.yml) - [packages/sendowl-packages.yml](packages/sendowl-packages.yml) - [components/sendowl-components.yml](components/sendowl-components.yml) - [security/sendowl-domain-security.yml](security/sendowl-domain-security.yml) - [well-known/sendowl-well-known.yml](well-known/sendowl-well-known.yml) ## What SendOwl does not publish Recorded so an agent does not go looking: no OpenAPI/Swagger, no AsyncAPI, no GraphQL, no MCP server, no A2A agent card, no `/.well-known/*` of any kind (404 on all four hosts), no `security.txt`, no first-party SDK in any package registry, no CLI, no public Postman collection, no dated changelog, no deprecation policy, no SLA, and no OAuth — so there are no scopes.