Metrilo Customers API

The Customers API from Metrilo — 4 operation(s) for customers.

OpenAPI Specification

metrilo-customers-api-openapi.yml Raw ↑
openapi: 3.1.0
info:
  title: Metrilo Tracking & CRM Categories Customers API
  version: v2
  description: Metrilo's server-side ingestion API for ecommerce analytics, CRM, and email marketing. Push customers, categories, products, and orders (single or batch) into a Metrilo project. All requests are POST with a JSON envelope of `{ time, token, params }`. Every backend endpoint except `/customer` requires an `X-Digest` header containing an HMAC-SHA256 of the raw request body keyed with the project's API Secret.
  contact:
    name: Metrilo
    url: https://github.com/Metrilo/custom-integration
  x-brevo: Metrilo is part of Brevo (acquired 2021).
servers:
- url: https://trk.mtrl.me/v2
  description: Metrilo tracking ingestion (production)
tags:
- name: Customers
paths:
  /customer:
    post:
      tags:
      - Customers
      operationId: createCustomer
      summary: Create or update a single customer
      description: Create or update one customer, identified by email. This is the only backend endpoint that does NOT require the X-Digest header.
      requestBody:
        required: true
        content:
          application/json:
            schema:
              $ref: '#/components/schemas/CustomerEnvelope'
      responses:
        '200':
          $ref: '#/components/responses/Ok'
        '400':
          $ref: '#/components/responses/BadRequest'
        '401':
          $ref: '#/components/responses/Unauthorized'
        '402':
          $ref: '#/components/responses/PaymentRequired'
        '500':
          $ref: '#/components/responses/ServerError'
        '502':
          $ref: '#/components/responses/BadGateway'
  /customer/batch:
    post:
      tags:
      - Customers
      operationId: batchCustomers
      summary: Bulk import customers
      security:
      - xDigest: []
      requestBody:
        required: true
        content:
          application/json:
            schema:
              $ref: '#/components/schemas/CustomerBatchEnvelope'
      responses:
        '200':
          $ref: '#/components/responses/Ok'
        '400':
          $ref: '#/components/responses/BadRequest'
        '401':
          $ref: '#/components/responses/Unauthorized'
        '403':
          $ref: '#/components/responses/Forbidden'
        '500':
          $ref: '#/components/responses/ServerError'
        '502':
          $ref: '#/components/responses/BadGateway'
  /customer/tag:
    post:
      tags:
      - Customers
      operationId: tagCustomer
      summary: Add tags to a customer
      security:
      - xDigest: []
      requestBody:
        required: true
        content:
          application/json:
            schema:
              $ref: '#/components/schemas/CustomerTagEnvelope'
      responses:
        '200':
          $ref: '#/components/responses/Ok'
        '400':
          $ref: '#/components/responses/BadRequest'
        '401':
          $ref: '#/components/responses/Unauthorized'
        '403':
          $ref: '#/components/responses/Forbidden'
  /customer/untag:
    post:
      tags:
      - Customers
      operationId: untagCustomer
      summary: Remove tags from a customer
      security:
      - xDigest: []
      requestBody:
        required: true
        content:
          application/json:
            schema:
              $ref: '#/components/schemas/CustomerTagEnvelope'
      responses:
        '200':
          $ref: '#/components/responses/Ok'
        '400':
          $ref: '#/components/responses/BadRequest'
        '401':
          $ref: '#/components/responses/Unauthorized'
        '403':
          $ref: '#/components/responses/Forbidden'
components:
  schemas:
    Customer:
      type: object
      required:
      - email
      properties:
        email:
          type: string
          format: email
        createdAt:
          type: integer
          format: int64
          description: Epoch ms
        firstName:
          type: string
        lastName:
          type: string
        phoneNumber:
          type: string
        subscribed:
          type: boolean
        tags:
          type: array
          items:
            type: string
          description: Merged with existing tags, not overwritten.
    CustomerEnvelope:
      allOf:
      - $ref: '#/components/schemas/Envelope'
      - type: object
        properties:
          params:
            $ref: '#/components/schemas/Customer'
    Envelope:
      type: object
      required:
      - token
      - params
      properties:
        time:
          type: integer
          format: int64
          description: Client event time in epoch milliseconds.
        token:
          type: string
          description: Project API Token (Settings -> Installation).
        params:
          type: object
    CustomerBatchEnvelope:
      allOf:
      - $ref: '#/components/schemas/Envelope'
      - type: object
        properties:
          params:
            type: array
            items:
              $ref: '#/components/schemas/Customer'
    CustomerTagEnvelope:
      allOf:
      - $ref: '#/components/schemas/Envelope'
      - type: object
        properties:
          params:
            type: object
            required:
            - email
            - tags
            properties:
              email:
                type: string
                format: email
              tags:
                type: array
                items:
                  type: string
  responses:
    ServerError:
      description: Server error while processing the request.
    BadGateway:
      description: Server error while accepting the request.
    PaymentRequired:
      description: Payment required for the project.
    Unauthorized:
      description: Invalid API token, or the X-Digest header is missing.
    BadRequest:
      description: Bad request (malformed payload).
    Forbidden:
      description: IP is on the ignore list, or the X-Digest signature is invalid.
    Ok:
      description: Request accepted for processing.
  securitySchemes:
    xDigest:
      type: apiKey
      in: header
      name: X-Digest
      description: HMAC-SHA256 digest of the raw JSON request body, keyed with the project's API Secret. Required for every backend endpoint except POST /customer.
x-provenance:
  generated: '2026-07-20'
  method: generated
  source: https://github.com/Metrilo/custom-integration
  note: Faithfully generated from Metrilo's public custom-integration API documentation (endpoints, request envelope, object fields, X-Digest auth, and HTTP status codes are all documented there). Metrilo publishes no OpenAPI of its own; this is an API Evangelist rendering of the documented backend tracking API. Field types reflect documented behavior only.