> ## Documentation Index
> Fetch the complete documentation index at: https://documentation.qonversion.io/llms.txt
> Use this file to discover all available pages before exploring further.

# MCP & API

> The two ways to drive Qonversion programmatically: the REST API v4 for your backend and the MCP server for AI agents, what each one reaches, how each one authenticates, and which one to pick.

The dashboard and the two programmatic surfaces work on the same resources. Everything listed under **What the surface covers** below is reachable from both — with a few exceptions under **Where the two surfaces differ** below, which is where most of the surprises live.

| | REST API v4 | MCP server |
| - | - | - |
| **Built for** | your backend, scripts, data pipeline | Claude, Cursor, Codex, Windsurf, your own agent |
| **Endpoint** | `https://api.qonversion.io/v4` | `https://mcp.qonversion.io/mcp` |
| **Authentication** | project Secret Key, server-side only | OAuth 2.1 against your Qonversion account |
| **Access** | whatever the Secret Key allows | per-tool OAuth scopes, mirroring your dashboard role |
| **Shape** | HTTP operations | tools; most wrap a single v4 operation |

The MCP server mirrors the v4 resource surface, and most of its tools wrap a single v4 operation. An AI client never handles the Secret Key.

## What the surface covers

Customers and users · identities · purchases · user properties · entitlements · products · remote configurations · experiments and groups · segments · analytics, cohorts and LTV · Apple Ads reports and connection status · exports · events · scheduled reports · integrations · project settings.

## Where the two surfaces differ

* **Apple Ads is read-only on both.** The report, the daily series and the connection status are available through REST API v4 — see [Apple Ads](/reference/v4/apple-ads) — and as MCP tools, where Apple Ads is a closed beta — see [Apple Ads via MCP](/docs/mcp-apple-ads). Both answer for accounts with Apple Ads enabled; other accounts receive `404`. You create and change campaigns in Apple Ads.
* **Some v4 resources are legacy.** Screens and automations remain callable for existing integrations, but the products behind them are no longer maintained. They are not a place to build something new.

## Which one to use

* **Your own server code, cron jobs, a warehouse sync** — the REST API v4. Start at [API reference](/reference/v4/overview) and [Authentication](/reference/v4/authentication).
* **An agent acting on your behalf** — the MCP server, so that access is scoped to your account role and revocable. Start at [For agents](/docs/for-agents) and [MCP Server](/docs/mcp-server).
* **Being told when something changes, instead of polling** — [webhooks](/docs/webhooks).

## Guardrails worth knowing before you wire anything up

* **Destructive tools do not fire on the first call.** Over MCP, `delete_*`, `revoke_*`, `detach_*` and the deprecated `regenerate_project_secret` return a short-lived token addressed to the human operator. Completing the action requires echoing the resource id verbatim and giving a reason, which is recorded in the audit log.
* **Secret Keys belong on a server.** Never ship one in an iOS, Android or web bundle. Rotate them in the dashboard — see [Project keys](/docs/project-keys).
* **Rate limits are not one number.** SDK requests are throttled on the client — see [Rate limits](/docs/rate-limits). The Apple Ads report and series are rate limited on both surfaces, and a `429` carries `Retry-After` — see [Apple Ads](/reference/v4/apple-ads) and [Apple Ads via MCP](/docs/mcp-apple-ads).
* **v3 is legacy.** It still answers for existing integrations and gets no new functionality. Build on v4 — start from [API reference](/reference/v4/overview); [API v3 (legacy)](/reference/overview) maps each v3 resource to its v4 counterpart.

## Next steps

<CardGroup cols={2}>
  <Card title="For agents" icon="robot" href="/docs/for-agents">
    Connect an agent in a few minutes, and read these docs as markdown.
  </Card>

  <Card title="MCP Server" icon="plug" href="/docs/mcp-server">
    Tool list, client-by-client setup, scopes and the confirmation flow.
  </Card>

  <Card title="API reference" icon="square-terminal" href="/reference/v4/overview">
    Base URL, authentication, pagination, errors, resource guides.
  </Card>

  <Card title="Webhooks" icon="bell" href="/docs/webhooks">
    Get subscription events pushed to your endpoint.
  </Card>
</CardGroup>


This documentation is built and hosted on [Mintlify](https://mintlify.com), a developer documentation platform.