Skip to main content
Foil’s public API covers five product surfaces:
  • Sessions - session result readback for backend verification and audit.
  • Fingerprints - visitor fingerprint readback for cross-session correlation.
  • Agents - proxy IP rotation decisions for agents.
  • Organizations - organization and API key lifecycle.
  • Webhooks and events - webhook endpoint management, signed event delivery, and event history with delivery diagnostics.

Base URLs

Managed Foil uses separate hosts for the CDN-hosted browser agent and the REST API.
The REST endpoints live under /v1/. The browser and mobile SDKs use a separate set of endpoints under /v2/collect/, documented in the Collect API reference. See Versioning for how the API evolves. The OpenAPI spec describes the REST endpoints.

Cross-cutting conventions

A handful of concerns apply to every endpoint. They have dedicated pages so they’re easy to link to and easy to keep accurate:

Authentication

Key types, scopes, and lifecycle. Start here.

Errors

Error envelope shape, status codes, retry semantics.

Pagination

Cursor-based pagination on the sessions, fingerprints, and API keys lists.

Rate limits

Organization defaults, response headers, retry strategy.

Versioning

What’s additive, what’s breaking, and how to pin.

Security and privacy

Crypto, infrastructure, and what you should disclose.

Endpoint groups

Sessions

Read the latest stored session result from your backend with a secret key.

Visitor fingerprints

Inspect visitor fingerprints with a secret key.

Agents

Check whether an agent should rotate its current proxy IP.

Organizations

Create organizations, and create, update, rotate, or revoke API keys for your own organization.

Webhooks and events

Manage webhook endpoints, verify signed deliveries, and review event history.