SDK activation, config and contacts

Endpoint POST /api/v1/sdk/activate, GET /api/v1/sdk/config, PUT /api/v1/sdk/contacts

The Odoo module uses these three calls. Any server-side integration that wants one-key-per-installation binding, the public key and the plan features can use them the same way.

1Activate

POST /api/v1/sdk/activate with the secret key. Body: instance_id (required, 8 to 128 characters; a stable fingerprint of the installation), base_url, platform, platform_version, terms_version, accepted_by (who accepted the Terms). Answers 200 {project, org, enabled, public_key, features: {security_monitoring, plan, seats}}; seats is null for unlimited. 409 {reason: 'instance_bound_elsewhere'} when this installation already reports to another project; 409 {reason: 'project_has_instance'} when this key already belongs to a different installation.

sh
curl https://in.blipit.io/api/v1/sdk/activate \
  -H "Content-Type: application/json" -H "X-Blipit-Key: <secret key>" \
  -d '{"instance_id":"7c1e0f9a2b3d4e5f6a7b8c9d0e1f2a3b","platform":"odoo","platform_version":"19.0","terms_version":"2026-09-28","accepted_by":"admin@example.com"}'

2Config

GET /api/v1/sdk/config with the secret key and X-Blipit-Instance. Answers {public_key, features}. Poll it occasionally (Odoo does every ten minutes) to notice a plan change or a new public key.

3Contacts

PUT /api/v1/sdk/contacts with the secret key and X-Blipit-Instance. Body {companies: [{id, name, people: [{id, name, email}]}]}. Distinct people count against the plan's seats together with members, invites and email rules. Answers 200 {used, seats, plan}, or 409 {reason: 'seats_exceeded', seats, used, plan} when the list would add people beyond the seats; a list that only shrinks is always accepted.

json
{
  "companies": [
    { "id": "1", "name": "Acme SG", "people": [{ "id": "2", "name": "Ana Lim", "email": "ana@example.com" }] },
    { "id": "2", "name": "Acme PH", "people": [{ "id": "7", "name": "Ben Cruz", "email": "ben@example.com" }] }
  ]
}

Good to know

  • After activation every request from that installation must carry X-Blipit-Instance; a mismatch gets 403 'this key is bound to a different instance'.
  • Once bound, the binding can only be changed from the Blipit dashboard.

Stuck? Email support@blipit.io. Keys and the exact DSN for each project are under API keys in app.blipit.io.