The Sender API is redesigned around two primitives.
Pre-launch update, 2026-09-18. The public v2 contract was later narrowed to plan execution and reconciliation before any external integrator depended on it. See The public API is now an execution API.
Plans are reusable workflow definitions. Correspondence is the record of
anything started, one-off or from a plan. A letter, an agreement, a routed
approval, a consent drive, and a form are kinds of correspondence rather than
separate APIs, so participants, minutes, covenants, and exports work the same
way on all of them.
Start at The model.
Breaking changes
- Credentials are organisation-scoped. The
/tenants/{tenant_id}path segment is gone: your key identifies the organisation, and its prefix identifies the plane (kpk_live_,kpk_test_). The base URL is nowhttps://api.keepable.co/sender/v2. - Recipient matching collapsed to one endpoint,
POST /recipient-checks, which answers about one identifier and is throttled per identifier. - Access delegation and recipient provisioning were dropped. Organisation membership and claim codes supersede them.
- The event catalogue collapsed.
participant.actedreplaces the kind-specific delivery, signature, and decision events;data.actnarrows it. - Pagination is
cursor/next_cursor, notnext/next_token. - Delivery metrics dropped the modelled environmental-impact estimates.
New
- Tokenized send. Address somebody by a declared name with no identifier. Keepable deposits the file and mints a single-use claim code; you hand it over on your own channel, and it redeems only inside the app after NIN verification with name congruence. No links, ever.
- Sensitive answers. A question can declare itself sensitive. The answer is stored encrypted, masked on the wire by default, and unmasked only by a deliberate, minuted request under its own scope.
- Work connections. Search your directory live and pull a file from your own drive in Workspace. Nothing is ever synced.
- Restricted correspondence. A file's row stays visible to the organisation while its contents go to its participants and named readers.
Migrating
Nothing is auto-migrated. The version is the /v2 in the URL and there is no
header to set, so porting is a matter of reading
The model and rewriting against the two primitives.
Sandbox is free and usable before approval, which is where to do it.
Amended 2026-07-31. The attested question type announced here
(type: "attested", attribute: "age_over_18") was withdrawn before launch
and is not in the contract: a verdict is Keepable's finding about somebody,
and a wire field the recipient's own client fills in could only ever be a
forgery. See Collecting responses.