Get started
Making requests
Every call to the MISSIN API is a persisted operation: send its name, its hash and your variables, never a query document of your own.
The endpoint
POST https://api.missin.co.uk/graphql/v1Persisted operations only
The API runs persisted operations: GraphQL documents the server already holds, each named by the SHA-256 hash of its text. A request names the operation and its hash and sends variables; it never sends a query document. A hash the server does not hold is refused.
{
"operationName": "CampaignsList",
"variables": {
"first": 20
},
"extensions": {
"persistedQuery": {
"version": 1,
"sha256Hash": "cc4c4616f86feca4fafac98d357af608114b690240d58999fe247adae9c52df6"
}
}
}Every operation a key can run, with its hash, its variables and a request to copy, is in the API reference.
A first request
Save the body above as request.json, then:
curl https://api.missin.co.uk/graphql/v1 \
-H "Authorization: Bearer sk_live_..." \
-H "Content-Type: application/json" \
-d @request.jsonThe response is standard GraphQL: data with the result, and errors when something went wrong (see Errors).
What a key can run
A key can run the operations in the API reference, and nothing else. Each page says what the operation needs: Read operations read your workspace and run with the key's own database role, so the database itself decides what comes back and a key never sees another workspace. Write operations change workspace data, and Admin operations also change settings and connections.
An operation the reference does not list is refused before it runs: with operation_not_public when it is not open to keys, and with insufficient_access when the key's level is below what the operation needs. An assistant can reach the same operations through the MISSIN MCP server.