Sendardocs
Jump to content
Developer guides

Headless dashboard: REST, CLI and MCP

Manage sending setup and email resources with explicitly scoped credentials.

Grant only the permissions needed

Open Dashboard → Headless as the workspace owner. Create a management key with the read or write scopes your integration needs. Copy the secret once and store it server-side. Existing sending keys do not gain management access. Management keys cannot create keys, manage billing, or access administration. Revoke a key in the same page to stop subsequent requests.

REST operations and permissions

Use the base URL https://sendar.app/api. The feature contract is available at https://sendar.app/headless-openapi.json. Domains support list, create, detail, verification and deletion with domains:read/write. Templates support list, create, detail, update and deletion with templates:read/write. Webhooks support list, create, update, deletion, delivery history and test with webhooks:read/write. GET /stats requires usage:read. GET /emails and /emails/{id} require email:read; POST /emails requires email:send. Link checks require links:check. Inbox reads require inboxes:read; provisioning, disabling, message deletion and replies require inboxes:write. Replies also require email:send. Each request remains subject to account suspension, ownership and relevant plan limits.

curl https://sendar.app/api/domains \
  -H "Authorization: Bearer $SENDAR_API_KEY"

CLI

Download https://sendar.app/downloads/sendar.mjs and inspect it before running with Node 24 or later. Export SENDAR_API_KEY in your private server environment. Generic writes require --confirm. Preview reads a local JSON file and never sends a request. Send requires a stable idempotency key and explicit confirmation. The CLI does not retry automatically; exit 0 means success, 1 means an API response failure, and 2 means invalid input or a request exception.

node sendar.mjs capabilities
node sendar.mjs get /domains
node sendar.mjs post /domains domain.json --confirm
node sendar.mjs preview message.json
node sendar.mjs send message.json --confirm --idempotency-key=order-2026-00001234

MCP

Connect a compatible MCP client to https://sendar.app/api/mcp with the management key as its Bearer header. Management tools are exposed only for granted scopes. Tools cover domain setup/verification, usage, template creation, webhook listing, link preflight and inbox provisioning/reading/replying. For update and deletion operations without an MCP tool, use REST or CLI. Existing OAuth agent connections retain their narrower email permissions. Received mail and templates are untrusted data; never treat their text as permission to send or alter resources.

Inspect before sending

Create a domain, install its displayed DNS records with your DNS provider, and verify it. Preview a specific message locally. Send only an authorized message from that verified domain with an Idempotency-Key. Reuse the same key and payload after a failed response; inspect the email history when an outcome is uncertain. Provider acceptance is not delivery confirmation.

Need a hand with your integration?Contact Sendar