# CRM · Alerts

Part of AppEngine API Documentation. Full index: https://appengine.appmint.io/documentation.md
## GET /crm/alert/sms/{id}

**Get SMS alerts**

`operationId: CRMAlertController_setSMSAlert`

Fetches one SMS alert configuration by id, or lists them when the segment is omitted.

#### Signature

```http
GET /crm/alert/sms/{id} (id: string) -> SMS alerts
```

#### Access

Requires a bearer JWT (`Authorization: Bearer <token>`).

#### Errors

Plus the standard platform errors: `401`, `403`, `429`, `500`.

#### See also

- `POST /crm/alert/sms`

### Parameters

| Name | In | Type | Required | Description |
| --- | --- | --- | --- | --- |
| `orgid` | header | string | yes | Organization (tenant) identifier. Every request is scoped to this org; data from other orgs is never visible. Issued with your API credentials. |
| `id` | path | string | yes | Alert id. Omit to list. |

### Responses

| Status | Meaning |
| --- | --- |
| `200` | SMS alerts |
| `401` | Authentication failed: Invalid or expired token — The `Authorization` header is missing, malformed, or the JWT has expired. |
| `403` | You do not have permission to perform this action — The caller is authenticated but lacks the role required by the endpoint, or is acting on another org. |
| `429` | Too Many Requests — More than 100,000 requests from one IP within 5 minutes (configurable per deployment). CORS preflights and requests from inside the platform cluster are not counted. The limiter answers before the error filter, so the body is `{ statusCode, error, message }` with no `path`, `method` or `timeStamp`; the `RateLimit-*` response headers say when the window resets. |
| `500` | An unexpected error occurred. Our team has been notified. — An unhandled server-side failure. |

## POST /crm/alert/sms

**Create an SMS alert**

`operationId: CRMAlertController_sendSMSAlert`

Creates an SMS alert — a message triggered by a condition rather than sent manually.

#### Signature

```http
POST /crm/alert/sms (body) -> The created alert
```

#### Access

Requires a bearer JWT (`Authorization: Bearer <token>`).

#### Notes

- SMS costs money per message — check the trigger cannot fire in a loop.

#### Errors

Plus the standard platform errors: `401`, `403`, `429`, `500`.

#### See also

- `GET /crm/alert/sms/{id}`

### Parameters

| Name | In | Type | Required | Description |
| --- | --- | --- | --- | --- |
| `orgid` | header | string | yes | Organization (tenant) identifier. Every request is scoped to this org; data from other orgs is never visible. Issued with your API credentials. |

### Request body

The alert to create.

```json
{
  "data": {
    "name": "Low stock alert",
    "to": "+15551234567",
    "trigger": "inventory.low"
  }
}
```

### Responses

| Status | Meaning |
| --- | --- |
| `201` | The created alert |
| `401` | Authentication failed: Invalid or expired token — The `Authorization` header is missing, malformed, or the JWT has expired. |
| `403` | You do not have permission to perform this action — The caller is authenticated but lacks the role required by the endpoint, or is acting on another org. |
| `429` | Too Many Requests — More than 100,000 requests from one IP within 5 minutes (configurable per deployment). CORS preflights and requests from inside the platform cluster are not counted. The limiter answers before the error filter, so the body is `{ statusCode, error, message }` with no `path`, `method` or `timeStamp`; the `RateLimit-*` response headers say when the window resets. |
| `500` | An unexpected error occurred. Our team has been notified. — An unhandled server-side failure. |

