API24x7

API24x7 documentation

Introduction

API24x7 lets you create hosted REST APIs, test any API and monitor uptime. This page documents the HTTP interface of the APIs you host and the REST API used by the mobile app.

Calling a hosted API

Every API project gets a base URL. Append the endpoint path:

https://www.api24x7.com/h/{your-api}/users/42

If your account uses wildcard subdomains the base URL looks like https://{your-api}.api24x7.app. The dashboard always shows the exact URL.

Send and receive JSON. Browsers can call hosted APIs directly: CORS is open by default and can be restricted to your own origins in the API settings.

Authentication

When an API is set to API key required (or an individual endpoint or collection requires auth), send your key in either header:

X-API-Key: a24_xxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxx
Authorization: Bearer a24_xxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxx

Keys are shown once at creation and stored only as a SHA-256 hash. Revoke a key at any time. Do not put keys in URLs.

Mock endpoints

An endpoint has a method, a path, a status code, optional headers, a body and an optional delay. Paths can contain parameters such as /users/{id}. Allowed response content types are JSON, plain text, XML and CSV.

Template placeholders

Response bodies can include placeholders that are replaced on every request:

PlaceholderResult
{{params.id}}Value of the {id} path parameter
{{query.page}}Query string value
{{body.user.name}}Value from the JSON request body
{{header.x-custom}}Request header value
{{uuid}}Random UUID v4
{{timestamp}} / {{iso_date}}Current Unix time / ISO 8601 date
{{random.int(1,100)}}Random integer in a range
{{random.name}} {{random.email}}Random person data
{{random.word}} {{random.sentence}} {{random.city}}Random text and places
{{random.bool}} {{random.color}} {{random.token}}Other random values

Values that come from the request are escaped, so a caller cannot break out of a JSON string.

Collections (CRUD)

A collection named products exposes:

GET    /products            list (page, per_page, sort, order, any field=value filter)
POST   /products            create
GET    /products/{id}       read
PUT    /products/{id}       replace
PATCH  /products/{id}       update some fields
DELETE /products/{id}       delete

List responses look like:

{ "data": [ { "id": 1, "name": "Mug", "price": 9.5, "created_at": "..." } ],
  "meta": { "page": 1, "per_page": 20, "total": 1, "last_page": 1 } }

Define field types (string, integer, number, boolean, email, url, date, array, object) to get validation. Invalid requests return 422 with an errors object.

Errors & limits

StatusMeaning
401Missing or invalid API key
403Your IP is not on the allow-list
404No endpoint or record matches
405Operation disabled for the collection
413Request body larger than 64 KB
422Validation failed
429Per-minute rate limit or daily quota reached (see Retry-After)

All errors are JSON: { "error": "code", "message": "Human readable text" }.

Heartbeat monitors

Create a heartbeat monitor and call its URL when your job finishes:

curl -fsS --retry 3 https://www.api24x7.com/heartbeat/YOUR_TOKEN

If no ping arrives within the interval plus one minute, the monitor goes down and you are alerted.

Mobile / token API

The mobile app uses a Bearer-token REST API under https://www.api24x7.com/api/v1. You can use it too.

POST https://www.api24x7.com/api/v1/auth/login
{ "email": "you@example.com", "password": "...", "device_name": "my-script" }
→ { "token": "1|abc...", "user": { ... } }

GET https://www.api24x7.com/api/v1/projects
Authorization: Bearer 1|abc...

Available resources: dashboard, me, projects, projects/{id}/endpoints, projects/{id}/resources, projects/{id}/keys, projects/{id}/logs, tester/send, monitors, status-pages, tools. You can also create long-lived personal tokens in Account → API tokens.

Blog publishing API

Site admins can publish posts programmatically with a token that only has the blog:write ability (create it in Admin → Settings).

POST https://www.api24x7.com/api/v1/admin/blog/posts
Authorization: Bearer YOUR_BLOG_TOKEN
{ "title": "My new post", "body": "<p>HTML</p>", "excerpt": "Summary", "category": "Guides",
  "meta_description": "SEO description", "published": true }
# or "published_at": "2026-12-01T09:00:00Z" to schedule; omit both to save a draft

GET    https://www.api24x7.com/api/v1/admin/blog/posts        list incl. drafts
PUT    https://www.api24x7.com/api/v1/admin/blog/posts/{id}   update (partial allowed)
DELETE https://www.api24x7.com/api/v1/admin/blog/posts/{id}
GET    https://www.api24x7.com/api/v1/blog/posts              public list of published posts

Scripts, iframes and inline event handlers are stripped from body. Slugs are generated from the title and made unique.

Start building, testing and monitoring today

Free plan. No credit card. Your first API is live in under two minutes.