Help

The REST API

Everything the dashboard does, the API does. The dashboard is a client of it, not a shortcut around it.

Authentication

Mint a token in settings. Send it as a bearer token:

Authorization: Bearer <your token>

Tokens are listed and revoked in the same place. Revoking one takes effect immediately.

There is no OAuth 2.0 flow. If you have read otherwise on this site, that was wrong and it has been corrected. Bearer tokens are the only mechanism.

The base

https://<your-subdomain>.sembr.co/api/v1/

The API is scoped to your organization by the address you call. A token issued by one organization cannot read another's data, and that is enforced in the database rather than by a filter somebody has to remember to apply.

What it covers

  • Members: GET|POST /members, GET|PATCH|DELETE /members/{id}, plus /members/{id}/categories, /members/{id}/restore, and /members/{id}/contact-log
  • Membership tiers: full CRUD at /membership-tiers
  • Member categories: full CRUD at /member-categories
  • Dues schedules: full CRUD at /dues-schedules
  • Invoices: GET /invoices, GET /invoices/{id}, and POST /invoices/{id}/send, /manual-payment, /void
  • Events: full CRUD at /events, plus /events/{id}/registrations and the check-in and cancel actions on a registration
  • Email templates: full CRUD, plus /preview and /send-test
  • Ask Sembr: /ai/bespoke-draft, /ai/subject-variants, /ai/tone-shift, /ai/generate-starter, and /ai/pool for your remaining allowance
  • Compliance: /dsar, /erasures, /audit-log, and /data-export
  • Settings: GET|PATCH /settings

What is not built

Outbound webhooks. Sembr cannot push an event to your endpoint. This is the single most requested thing and it is genuinely not there. Anything that waits to be told, including a Zapier or Make integration, has to poll for now.

A published OpenAPI document. Planned.

Rate limits

There are limits, and they are set for the data volume a membership organization actually produces rather than for a scraper. If you hit one you will get a 429 with a header telling you when to retry, not a silent failure.

Errors

Errors come back as JSON with a status code that means what it says. A 422 carries per-field validation messages. A 404 on a record that exists in another organization is a 404, not a 403, because telling you the difference would tell you the record exists.

Building something?

Tell us what you are wiring up. It shapes what we build next.