The Brevily API
Everything the console does to a link, your own code can do too: the same checks, the same permissions and the same plan limits, answered in JSON.
What it can do
Links
Create, list, read, change, disable and delete short links: the destination, your own back-half and domain, tags, a go-live date and an expiry, a click limit, a password, UTM tags and the preview a chat shows.
QR codes
The code for any link, as SVG or PNG, plain or in your colours with your logo.
Analytics
Each link’s clicks day by day, its unique visitors and QR scans, and where they came from: countries, devices, browsers, systems and referrers. Exports as CSV.
Tags
Tag links by person, team, campaign, channel, product or region, and read the numbers by tag.
Conversions
Report a sign-up or a sale against the click that led to it, with an amount and your own order id, and see what each link earned.
Webhooks and GA4
A JSON POST to your server for every human click, or the same click sent to a Google Analytics 4 property, retried for hours when your side is down.
Keys, signatures and signed webhooks
An API key per job
A key is made in the console, for the organisation or for one person, with only the permissions it needs, and never more than the person who made it holds. It expires when you choose, and rolling or revoking it takes one click.
Two headers, or a signature
Each call carries the key’s ID and secret in two headers, or a signature made with the secret (HMAC-SHA256 over the request), so the secret never travels. A browser’s session never counts.
Webhooks you can check
Every delivery is signed with its own secret, timestamp included, so your server can refuse anything that did not come from Brevily, or that is being replayed.
The reference lives in the console
Every call with its fields and answers, the webhook body and how to check it, conversions and the errors: in the console once you are signed in.