Adset.ProAdset.ProKnowledge base
Home/Integrations/Public HTTP API

Public HTTP API

The document describes how third-party integrations (BI systems, scripts, dashboards) can authenticate and retrieve statistics data through the platform's public HTTP API.

Base URL: https://adset.pro (production). Swagger UI: https://adset.pro/api/docs (OpenAPI 3.0).


TL;DR (checklist)

  1. In the UI cabinet (section API keys) create a PAT (Personal Access Token). Copy the token immediately — it is shown only once.

  2. Pass the token in each request header Authorization: Bearer <token>.

  3. All public statistics endpoints live under the prefix /api/stats/**.

  4. The request body for /api/stats/query is StatsQueryDto (see below).

  5. The scopes of the PAT are divided: api:stats (read), api:stats:export (CSV export), api:stats:meta (dictionaries).

  6. An alternative to PAT is OAuth 2.0 (Authorization Code + PKCE) via /oauth/authorize → /api/oauth/token. Discovery: /.well-known/oauth-authorization-server.


1. Authentication

1.1 Personal Access Token (PAT) — recommended for scripts

Token prefix: pat_… (~64 characters). Suitable for server integrations and curl.

Usage

curl -X POST 'https://adset.pro/api/stats/meta/metrics' \
  -H 'Authorization: Bearer pat_XXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXX'

The prefix pat_ is accepted only on paths /api/*. A separate key of type mcp (prefix mcp_) is needed on /mcp.

1.2 OAuth 2.0 (Authorization Code + PKCE) — for applications

Parameter

Value

Authorization endpoint

GET /oauth/authorize?client_id=…&redirect_uri=…&response_type=code&scope=api:stats&code_challenge=…&code_challenge_method=S256&state=…

Token endpoint

POST /api/oauth/token (grant_type=authorization_code or refresh_token)

Token prefix

oat_…

Discovery (RFC 8414)

GET /.well-known/oauth-authorization-server

Protected resource (RFC 9728)

GET /.well-known/oauth-protected-resource

Client registration

POST /api/oauth/register (RFC 7591 Dynamic Client Registration)

OAuth tokens oat_ are accepted both on /api/* and on /mcp.

1.3 API access scopes

Scope

What it allows

api:stats

POST /api/stats/query — read statistics aggregates

api:stats:export

POST /api/stats/export/csv — CSV export

api:stats:meta

GET /api/stats/meta/* — dictionaries of fields, metrics, groups

Effective rights = token scopes ∩ RBAC role of the owner user. BUYER sees only their statistics, TEAM_LEAD — team statistics according to resourceAccess rules, etc.

1.4 Standard authorization errors

HTTP

error

Reason

401

invalid_token

token is missing / expired / revoked

401

invalid_token_prefix

pat_ used on /mcp or mcp_ on /api

403

insufficient_scope

the token does not have the required scope (see table 1.3)

403

forbidden

RBAC user check failed


2. Public API statistics endpoints

The base prefix is /api/stats. The request bodies are JSON, responses are application/json (or text/csv for export).

Method

Path

Scope

Purpose

POST

/api/stats/query

api:stats

Get report (metrics × groupings + filters)

POST

/api/stats/export/csv

api:stats:export

Same selection, but in CSV format (no pagination, up to 100,000 rows)

GET

/api/stats/meta/metrics

api:stats:meta

Metrics catalog

GET

/api/stats/meta/groups

api:stats:meta

Groupings catalog

GET

/api/stats/meta/filters

api:stats:meta

List of filterable fields

GET

/api/stats/meta/distinct?field=&q=&limit=

api:stats:meta

Suggestions (autocomplete) for field value

GET

/api/stats/meta/os-versions?q=&limit=

api:stats:meta

Suggestions for OS versions

2.1 POST /api/stats/query

Request body (StatsQueryDto):

{
  "time": {
    "preset": "last7",        // OR from/to
    "from":  "2026-05-01 00:00:00",
    "to":    "2026-05-20 23:59:59",
    "timezone": "UTC"
  },
  "groups":  ["day", "cmp_campaign"],     // see Section 5
  "metrics": ["clicks", "cpa_accept", "revenue", "roi"],
  "filters": [
    { "field": "user_country", "op": "in",  "value": ["US", "CA"] },
    { "field": "cmp_offer",    "op": "eq",  "value": "65f0…" }
  ],
  "pagination": { "page": 1, "limit": 100 },
  "sort": { "field": "clicks", "order": "desc" },
  "attributionWindow": { "hours": 24, "eventType": "click" }
}

Rules

  • time is required; you must pass either preset, or from (optionally with to).

  • groups — an array of keys from the grouping table (see section 5). An empty array → aggregate "total".

  • metrics — an array of metric keys from section 6. Defaults to `[

[!] Перевод выполнен с усечением исходника — проверьте оригинал.