Recued
Menu
← Back to packs

Customer Messaging - OneSignal

by recued-core v2 app_pack 6 views

One-install OneSignal REST API front door over app-key messaging/audience operations and a separate organization-key administration leaf. The suite publishes 51 executable operations covering 49 of 59 declared official contracts (46 of 56 distinct routes); the prior root exposed 15 operations. Version 2 preserves all 15 operation IDs and six workflow IDs while adding current message-channel, template, segment, custom-event, user, subscription, legacy-player, Live Activity, in-app-message, audit, app, and API-key metadata capabilities. 10 fail-closed exclusions cover secret-returning key issuance/rotation, credential-bearing app responses, export and history capabilities, URL-carried capability tokens, and one superseded token-registration route. The current official https://api.onesignal.com origin replaces the legacy /api/v1 enrollment base. App and organization keys are distinct connection slots because OneSignal assigns them different authority. The multi-document authority cannot be represented by one honest openapi_source; a hash-pinned generated fixture accounts for every current reference page plus the immutable legacy OpenAPI. Reads are uncached and not approval-gated, every mutation requires approval, unsafe JSON integers remain exact strings, provider credentials stay connection-owned, and no synced Source is claimed without live field-presence proof.

Trust & control

What installing this whole pack would let it do. Recued grants these permissions at install — review them there before approving.

What it's allowed to do

Destructive Web APIs onesignal external change
Read: notification.search · No approvalRead: notification.read · No approvalWrite: notification.create · Always asksDestructive: notification.cancel · Always asksRead: outcome.search · No approvalRead: user.read · No approvalRead: user.identity.read · No approvalAdmin: user.create · Always asksAdmin: user.update · Always asksAdmin: user.identity.update · Always asksAdmin: subscription.create · Always asksAdmin: subscription.update · Always asksAdmin: segment.create · Always asksRead: player.search · No approvalRead: player.read · No approvalAdmin: subscription.identity.update · Always asksWrite: custom_event.create_batch · Always asksAdmin: template.create · Always asksDestructive: user.identity.delete · Always asksDestructive: segment.delete · Always asksDestructive: subscription.delete · Always asksDestructive: template.delete · Always asksDestructive: user.delete · Always asksWrite: notification.email.create · Always asksRead: subscription.identity.read · No approvalWrite: notification.push.create · Always asksWrite: notification.sms.create · Always asksWrite: live_activity.start · Always asksDestructive: subscription.transfer · Always asksDestructive: live_activity.update · Always asksAdmin: segment.update · Always asksAdmin: template.update · Always asksRead: segment.read · No approvalRead: segment.search · No approvalRead: template.read · No approvalRead: template.search · No approvalAdmin: player.create · Always asksAdmin: player.update · Always asksAdmin: user.tags.update_legacy · Always asksDestructive: player.delete · Always asksDestructive: live_activity.end_legacy · Always asksRead: in_app_message.eligible.search · No approvalRead: notification.search_all · No approvalRead: player.search_all · No approval

Data it touches

SurfacesWeb APIs

About

Tags

pack:onesignalonesignalmessagingpushemailsmsnotificationsaudiencesegmentsuserssubscriptionstemplateslive-activitiesworkflowapicomposition