Metrilo Customers API
The Customers API from Metrilo — 4 operation(s) for customers.
The Customers API from Metrilo — 4 operation(s) for customers.
openapi: 3.1.0
info:
title: Metrilo Tracking & CRM Categories Customers API
version: v2
description: Metrilo's server-side ingestion API for ecommerce analytics, CRM, and email marketing. Push customers, categories, products, and orders (single or batch) into a Metrilo project. All requests are POST with a JSON envelope of `{ time, token, params }`. Every backend endpoint except `/customer` requires an `X-Digest` header containing an HMAC-SHA256 of the raw request body keyed with the project's API Secret.
contact:
name: Metrilo
url: https://github.com/Metrilo/custom-integration
x-brevo: Metrilo is part of Brevo (acquired 2021).
servers:
- url: https://trk.mtrl.me/v2
description: Metrilo tracking ingestion (production)
tags:
- name: Customers
paths:
/customer:
post:
tags:
- Customers
operationId: createCustomer
summary: Create or update a single customer
description: Create or update one customer, identified by email. This is the only backend endpoint that does NOT require the X-Digest header.
requestBody:
required: true
content:
application/json:
schema:
$ref: '#/components/schemas/CustomerEnvelope'
responses:
'200':
$ref: '#/components/responses/Ok'
'400':
$ref: '#/components/responses/BadRequest'
'401':
$ref: '#/components/responses/Unauthorized'
'402':
$ref: '#/components/responses/PaymentRequired'
'500':
$ref: '#/components/responses/ServerError'
'502':
$ref: '#/components/responses/BadGateway'
/customer/batch:
post:
tags:
- Customers
operationId: batchCustomers
summary: Bulk import customers
security:
- xDigest: []
requestBody:
required: true
content:
application/json:
schema:
$ref: '#/components/schemas/CustomerBatchEnvelope'
responses:
'200':
$ref: '#/components/responses/Ok'
'400':
$ref: '#/components/responses/BadRequest'
'401':
$ref: '#/components/responses/Unauthorized'
'403':
$ref: '#/components/responses/Forbidden'
'500':
$ref: '#/components/responses/ServerError'
'502':
$ref: '#/components/responses/BadGateway'
/customer/tag:
post:
tags:
- Customers
operationId: tagCustomer
summary: Add tags to a customer
security:
- xDigest: []
requestBody:
required: true
content:
application/json:
schema:
$ref: '#/components/schemas/CustomerTagEnvelope'
responses:
'200':
$ref: '#/components/responses/Ok'
'400':
$ref: '#/components/responses/BadRequest'
'401':
$ref: '#/components/responses/Unauthorized'
'403':
$ref: '#/components/responses/Forbidden'
/customer/untag:
post:
tags:
- Customers
operationId: untagCustomer
summary: Remove tags from a customer
security:
- xDigest: []
requestBody:
required: true
content:
application/json:
schema:
$ref: '#/components/schemas/CustomerTagEnvelope'
responses:
'200':
$ref: '#/components/responses/Ok'
'400':
$ref: '#/components/responses/BadRequest'
'401':
$ref: '#/components/responses/Unauthorized'
'403':
$ref: '#/components/responses/Forbidden'
components:
schemas:
Customer:
type: object
required:
- email
properties:
email:
type: string
format: email
createdAt:
type: integer
format: int64
description: Epoch ms
firstName:
type: string
lastName:
type: string
phoneNumber:
type: string
subscribed:
type: boolean
tags:
type: array
items:
type: string
description: Merged with existing tags, not overwritten.
CustomerEnvelope:
allOf:
- $ref: '#/components/schemas/Envelope'
- type: object
properties:
params:
$ref: '#/components/schemas/Customer'
Envelope:
type: object
required:
- token
- params
properties:
time:
type: integer
format: int64
description: Client event time in epoch milliseconds.
token:
type: string
description: Project API Token (Settings -> Installation).
params:
type: object
CustomerBatchEnvelope:
allOf:
- $ref: '#/components/schemas/Envelope'
- type: object
properties:
params:
type: array
items:
$ref: '#/components/schemas/Customer'
CustomerTagEnvelope:
allOf:
- $ref: '#/components/schemas/Envelope'
- type: object
properties:
params:
type: object
required:
- email
- tags
properties:
email:
type: string
format: email
tags:
type: array
items:
type: string
responses:
ServerError:
description: Server error while processing the request.
BadGateway:
description: Server error while accepting the request.
PaymentRequired:
description: Payment required for the project.
Unauthorized:
description: Invalid API token, or the X-Digest header is missing.
BadRequest:
description: Bad request (malformed payload).
Forbidden:
description: IP is on the ignore list, or the X-Digest signature is invalid.
Ok:
description: Request accepted for processing.
securitySchemes:
xDigest:
type: apiKey
in: header
name: X-Digest
description: HMAC-SHA256 digest of the raw JSON request body, keyed with the project's API Secret. Required for every backend endpoint except POST /customer.
x-provenance:
generated: '2026-07-20'
method: generated
source: https://github.com/Metrilo/custom-integration
note: Faithfully generated from Metrilo's public custom-integration API documentation (endpoints, request envelope, object fields, X-Digest auth, and HTTP status codes are all documented there). Metrilo publishes no OpenAPI of its own; this is an API Evangelist rendering of the documented backend tracking API. Field types reflect documented behavior only.