| GET | /healthz | Database is answering. |
| GET | /v1/plans | Prices a public signup can choose. |
| POST | /v1/accounts | Start a 30-day trial without a card. The signup token lasts one hour. |
| GET | /v1/accounts/{account_id} | Status, plan, email, and whether the email is confirmed. |
| GET | /v1/email/verify | Confirm the email. The confirmation link lands here. |
| POST | /v1/accounts/{account_id}/verification-email | Send the confirmation email again. |
| POST | /v1/accounts/{account_id}/checkout | Open Stripe Checkout for the $1 per account/month subscription. No usage charges. |
| GET | /v1/checkout/success | Browser return after Checkout. Marks the account active when the session is paid. |
| GET | /v1/checkout/cancelled | Browser return when Checkout is cancelled. No charge. |
| POST | /v1/stripe/webhook | Stripe notifies this process. An integrator does not call it. |
| POST | /v1/api-keys | Issue an API key. The secret is in this response only. |
| GET | /v1/whoami | Whose key this is. The secret is not returned. |
| GET | /v1/setup | Whether this account has a pixel installed. |
| POST | /v1/pixels | Mint a pixel for a site and return the install snippet. |
| GET | /v1/pixels | Pixels on this key's account, oldest first. Snippets are not included. |
| GET | /v1/pixels/{pixel_id} | One pixel, including the current snippet. |
| POST | /v1/pixels/{pixel_id}/check | Fetch `https://{domain}/` and record whether the HTML contains this pixel id. |
| PATCH | /v1/pixels/{pixel_id} | Change the domain. Refused after the pixel is installed. |
| DELETE | /v1/pixels/{pixel_id} | Delete a pixel that is not installed. |
| GET | /v1/pixels/{pixel_id}/snippets/{action} | Extra paste snippet for one commerce action. |
| POST | /v1/pixels/{pixel_id}/email-snippet | Email the immediate install snippet. |
| GET | /v1/pixels/{pixel_id}/contacts | Read resolved people. Pass `on` or `after`, one of them. |
| POST | /v1/pixels/{pixel_id}/contacts | Store people that are already resolved. A customer read uses GET. |
| GET | /v1/billing/quote | What this account would owe. This call does not charge. |
| POST | /v1/pixels/{pixel_id}/consent | Turn on the permission popup and publish the policy. |
| GET | /v1/pixels/{pixel_id}/consent | Consent log for one pixel, newest first, at most 200 rows. |
| GET | /px/{pixel_id}.js | The permission popup. Browsers load this. It is not cached. |
| GET | /v1/policy/{pixel_id} | The current privacy notice as HTML. |
| POST | /v1/consent/record | The popup writes one choice. A saved choice is 202. An ignored choice is 204 with an empty body. |
| GET | /v1/consent/check | Whether the latest receipt allows a purpose. |
| GET | /v1/consent/receipt | The latest receipt for a visitor, with a signature. |
| POST | /v1/consent/verify | Check a receipt signature. |
| GET | /pixel.js | Identification script referenced by the immediate snippet. |
| GET | /pixel.dev.js | Dev beacon. Customer installs use `/pixel.js` or the consent tag. |
| GET | /pixel_popup.js | Popup script referenced by the immediate snippet. |
| GET | /pixels/{pixel_id}/p.js | Redirect to Delivr's tag for this pixel id. |
| GET | /external_api/install-pixel/delivr-pixel | Whether this pixel id belongs on this host. Used by the tag, not by account setup. |
| POST | /v1/accounts/{account_id}/activate | Mark an account active without changing its plan. A paid customer key receives 403. |
| POST | /v1/pixels/pipeline | Mint a `cms` or `utm` pixel on a customer's paid account. A paid key receives 403. |
| GET | / | HTML front. The Host header picks the pixel site, the permission site, or the API home. |
| GET | /site/pixel | Pixel marketing page. |
| GET | /site/permission | Permission marketing page. |
| GET | /demo | HTML form that provisions a consent tag on the shared demo account. |
| POST | /demo/provision | Form post for the demo page. Creates or reuses a pixel on the demo account and turns consent on. |
| GET | /log | HTML page. A person pastes a pixel id and an API key to read that pixel's consent log. |