Dark mode
API access overview

API access overview

This page is for developers who want to connect their own code, scripts, or AI tools to Helpin. It explains which integration points you can use today and which ones you can't.

Short answer

Helpin has a public REST API for reading and changing your workspace's tasks, planning, documents, CRM, and support data. It uses bearer tokens from automation accounts that a workspace manager creates and scopes. See Helpin REST API to get started.

The HTTP API that the Helpin web app itself uses with your signed-in session is a different, internal API. It can change without notice, and you can't create a long-lived key for it. Don't build integrations against it.

These are the supported integration points:

You want to…

Use

Credential

Read and update workspace data from your own code, scripts, or CI jobs

Helpin REST API

Automation account token (bearer)

Let an AI client, such as Claude, Codex, Cursor, or VS Code, read and update tasks, documents, CRM, or support

Helpin MCP server

OAuth sign-in for each user

Run headless automation that speaks MCP

Helpin MCP server with a service account

Service account token (bearer)

Add chat, help articles, and visitor tracking to your website or app

Widget SDK (lib.js or @helpin-ai/sdk-js)

Public widget key, plus an optional server-signed identity

Helpin REST API

The REST API is the simplest way to connect your own code to Helpin. It exposes a curated, versioned set of endpoints under https://api.helpin.ai/public/v1 and publishes its OpenAPI description at https://api.helpin.ai/public/v1/openapi.json. It uses the same automation-account tokens, scopes, read-only mode, and permission checks as the MCP server, so a token can never do more than its account and the workspace policy allow.

Helpin MCP server

Helpin MCP is in controlled beta. A workspace manager must enable it for your workspace before anyone can connect.

The Helpin MCP server is the supported way to read and change workspace data from code. It uses the open Model Context Protocol over Streamable HTTP, so any MCP-compatible client or SDK can call it. Each request carries a bearer credential:

  • A person's connection uses OAuth. Each user approves scopes on a consent screen and can revoke access at any time.

  • Headless automation uses a service account token. A workspace manager creates the service account in Settings → AI Clients → Service accounts and picks its scopes and toolsets. The token is shown only once.

Every call is checked against the caller's current permissions and the workspace's MCP policy. Service accounts don't bypass permissions.

To start, see Connect AI clients to the Helpin MCP server. For every tool, its inputs, and the scope it needs, see MCP tools & resources reference.

Widget SDK

To put Helpin on your own website or app, use the Widget SDK. It loads the chat widget, identifies signed-in users, opens help articles, and tracks events. It authenticates with your public widget key, which is safe to include in page HTML. To prove who a signed-in visitor is, your backend signs their identity with a separate secret that never goes to the browser.

Webhooks

Helpin doesn't send outgoing webhooks to your endpoints yet. To react to changes in Helpin, poll through the MCP server with a service account, or use Helpin's built-in automations inside the product.

Limits of this page

This page covers integration points that customers can use. It doesn't list the web app's internal endpoints, and those endpoints aren't a supported contract.

Was this article helpful?