# Whisperr, Inc. > Autonomous customer-retention platform. Whisperr ingests product events > ("churn signals"), decides on an intervention, generates the content, and > delivers it — replacing a lifecycle marketing team operating campaigns. The > public API is a small, strict, write-oriented ingestion surface plus a > read-only user/decision surface. Generated by API Evangelist on 2026-08-13. Whisperr does not publish an llms.txt of its own (probed: whisperr.net/llms.txt returns the marketing SPA's HTML shell; docs.whisperr.net/llms.txt and api.whisperr.net/llms.txt both 404). This file is generated from the provider's own published artifacts. ## What an agent needs to know first - Base URL: https://api.whisperr.net - Auth: `X-API-Key: wrk_...` or `Authorization: Bearer wrk_...`. The ingestion key is PUBLISHABLE — it ships in client bundles and can only ingest events for its own app. Treat it like a PostHog project key, not a secret. - Idempotency: every event's `context` MUST contain `$message_id`, a per-event key. Generate it ONCE when the event is created and send the identical value on every retry. The server deduplicates on it. - Strictness: unknown fields are REJECTED. A misspelled field fails the whole request with a 4xx rather than being ignored. There is no forgiving mode. - A single malformed event fails an entire batch of up to 500. Validate first. - Errors: `{"error":{"code","message","request_id"}}` — not RFC 9457. The set of `code` values is not published. - Rate limits: no published numbers. 429 means back off; honor `Retry-After` when present. There are no RateLimit-* headers. ## Response classification (the provider's own contract) - 2xx — delivered, dequeue. - 401 / 403 — auth. Stop sending, RETAIN the payload; retrying will not help. - 429, 5xx, network error, timeout — transient. Bounded exponential backoff; RETAIN on exhaustion. - any other 4xx — malformed. DROP and log; it will never succeed. ## API reference - [Overview and auth](https://docs.whisperr.net/api/overview/): base URL, the three ingestion endpoints, both auth headers, strict validation. - [Track events](https://docs.whisperr.net/api/events/): the event object — external_user_id, event_type, occurred_at, properties, context. - [Identify users](https://docs.whisperr.net/api/identify/): traits, and channels (email / sms / push) with opt-in state. - [Delivery, retries and idempotency](https://docs.whisperr.net/api/delivery/): the response classification table, $message_id rules, backoff. - [Event design](https://docs.whisperr.net/concepts/events/): which events predict churn and how to name them. - [OpenAPI 3.0.3](https://api.whisperr.net/openapi.json): the full runtime document — 46 paths, 53 operations, 64 schemas. ## Public operations (API-key authenticated) - `POST /v1/events/batch` — trackEventBatch. Up to 500 events. Preferred. - `POST /v1/events/track` — trackEvent. Single event, for one-off calls. - `POST /v1/identify` — identifyUser. Traits and contact channels; idempotent. - `GET /v1/users/{external_id}` — getUser. - `GET /v1/users/{external_id}/state` — getUserState. - `POST /v1/decisions/preview` — previewDecision. Dry run: evaluates which intervention would be selected WITHOUT dispatching it to an end user. The remaining 46 operations in the document are dashboard and internal operations authenticated with a Supabase JWT tied to a human console session, plus an inbound Postmark delivery webhook. They are not an agent surface. ## Event rules - `event_type` must be lowercase snake_case matching `^[a-z0-9]+(?:_[a-z0-9]+)*$`. Prefer object_verb past tense: `payment_failed`, `trial_expired`, `subscription_cancelled`. - `occurred_at` is RFC3339 UTC, millisecond precision, `Z` suffix. Accepted window is +5 minutes to −30 days. Capture at event time, not send time. - `external_user_id` is YOUR stable user id. The same id on frontend and backend merges both into one timeline. Whisperr mints no id of its own. - `properties` serializes empty as `{}`, never `[]`. - Only event types configured during onboarding drive interventions; others are accepted but inert. ## SDKs (all first-party, all conformance-tested) - JavaScript / browser: `@whisperr/web` (npm) - React: `@whisperr/react` — Next.js: `@whisperr/next` - Node.js: `@whisperr/node` - React Native / Expo: `@whisperr/react-native` - Python (+ Django): `whisperr` (PyPI) - PHP (+ Laravel): `whisperr/php` (Packagist) - .NET: `Whisperr` (NuGet) - Flutter: `whisperr` (pub.dev) - Swift: `WhisperrAI/whisperr-swift` (Swift Package Manager) ## Wire contract and conformance - [whisperr-spec](https://github.com/WhisperrAI/whisperr-spec) — the single source of truth. `SPEC.md` is the human contract; `conformance/wire.json`, `conformance/behavior.json` and `conformance/push.json` are executable fixtures every official SDK runs in CI. If you build your own client, these are the ground truth. ## What Whisperr does NOT publish Recorded so an agent does not go looking: no MCP server, no A2A agent card, no GraphQL, no AsyncAPI or customer-facing webhooks, no status page, no changelog, no deprecation policy, no SLA, no pricing or plans, no sandbox or test credentials, no CLI, no security.txt, no OAuth, and no compliance certifications or trust center. There is a live unauthenticated health endpoint at https://api.whisperr.net/health. ## Company - [Website](https://whisperr.net) — [Blog](https://whisperr.net/blog) - [Developer docs](https://docs.whisperr.net/) — [GitHub](https://github.com/WhisperrAI) - [Get access](https://whisperr.net/get-access) — [Terms](https://whisperr.net/terms) - Serves SaaS, DTC / subscription commerce, and mobile games. 500 Global portfolio company.