Skip to main content
An agent can start a Datalyr signup, hand the person one link, collect a read key, and verify the install end to end. A person pays and clicks Approve. This page is the exact flow across that boundary.

The hand-offs

Step 1: start the signup

POST /v1/signup is the only Datalyr API route that needs no key. Send key_request to get a read key once the person pays.
Store signup_secret. We return it once and never again. It authorizes the status reads in step 4 and nothing else. Nothing is created by this call except the pending signup. No account, workspace, or key exists until the person pays.

Step 2: the person pays

Give the person checkout_url. It opens a page with the workspace name, the domain, the plan, and their email, which they can edit. They select Continue to payment and complete a Stripe checkout hosted by our billing provider. Paying is the verification. We also send a verification email as a backup path, and its link opens the same checkout page. Do not ask the person for card details, and do not accept any.

Step 3: the person approves the key

The page after payment shows an approval card for the key you requested in step 1. It names the scope, the workspace, and the requester. The person selects Approve or Deny. An address that already has a Datalyr account gets the workspace, but no session in the paying browser. That person signs in from the email link, then sees the card.

Step 4: collect the key

Poll the status URL with the signup secret until status is paid.
An unknown id and a wrong secret both return the same 404. This route never returns a key. Then poll poll_url with the same signup secret. The first poll after Approve returns the key in key. Later polls return key_id and key_prefix without it. See Authentication for every status.

Step 5: setup

Ask the person to install tracking. Point them at Install web tracking or Mobile. To create conversion rules or trackable links, file a key request for the write scope you need. The workspace owner approves it. See API keys.

Step 6: confirm it works

GET /v1/onboarding needs a key, so it answers only after step 4. Read next_steps, drive one item, then read it again.
Confirm the install by watching first_event_seen_at change from null to a timestamp after the person adds the snippet. A 200 on the key alone proves only that the key works.

What an agent cannot do

These four are human actions by design, not gaps to work around. MCP has no signup tool for the same reason. MCP needs an OAuth token, which needs an account that already exists. Use POST /v1/signup before that point, and get_onboarding_status after it.