Mobile edge API
The mobile edge contract is public for auditability and SDK development, but normal applications should use an Engage SDK instead of calling these endpoints directly. The SDK owns credential storage, recovery, batching, retry, generation handling, cache consistency, and receipt durability.
Download the OpenAPI 3 contract.
Endpoint families
| Endpoint | Authentication | Purpose |
|---|---|---|
POST /v1/sdk/installations | X-Engage-App-Key | bootstrap or recover an installation session |
GET /v1/sdk/installation | installation bearer | inspect current generation and runtime states |
POST /v1/sdk/installation/binding-code | installation bearer | issue a short-lived identity binding code |
POST /v1/sdk/operations:batch | installation bearer | submit durable profile, event, subscription, push, and receipt operations |
POST /v1/sdk/sync | installation bearer | retrieve remote state, content, flags, preferences, and workflow data |
GET /v1/sdk/inbox | installation bearer | page inbox metadata |
POST /v1/sdk/inbox/operations:batch | installation bearer | apply inbox mutations and receipts |
POST /v1/sdk/inbox/renderings:resolve | installation bearer | resolve immutable rendering snapshots |
PUT /v1/sdk/privacy/revocations/{operationId} | revocation credential | converge remote privacy erasure |
The server-side identity transition endpoint shares the /v1 API but requires an environment access key rather than an installation credential.
Bootstrap
Bootstrap uses the public app key and platform metadata. The response contains installation, revocation, and recovery credentials. A direct client implementation must store each with platform-appropriate protection and never expose them to application analytics or logs.
Batching and generation
Every client mutation has a stable operation ID. Batches return per-operation acceptance or a stable error. Binding transitions advance generation so stale operations cannot cross identities.
Sync cursors
Sync is cursor-based and server-signed. Clients persist the last accepted cursor and apply versioned state atomically. Do not construct or edit cursors.
Why SDKs are required
A hand-written HTTP integration can appear to work in the foreground while missing cold push initialization, process death recovery, token rotation, retry bounds, account-generation safety, inbox state convergence, and privacy revocation. Use the OpenAPI contract to inspect or contribute to SDK behavior, not to bypass it in a product app.