# CRM · Chat

Part of AppEngine API Documentation. Full index: https://appengine.appmint.io/documentation.md
## GET /crm/chat-message/get/{id}

**Get chat messages**

`operationId: CRMController_getChatMessages`

The caller's chat messages. Supply `id` for one; omit the segment to list them all.

#### Signature

```http
GET /crm/chat-message/get/{id} (id: string) -> Chat messages
```

#### Access

Requires a bearer JWT (`Authorization: Bearer <token>`).

#### Errors

| Status | Code | Message | When | What to do |
| --- | --- | --- | --- | --- |
| `401` | CUSTOMER_REQUIRED | customer is required | No signed-in customer or user could be resolved. | Sign in — these routes are scoped to the caller. |

Plus the standard platform errors: `403`, `429`, `500`.

#### See also

- `POST /crm/chat-message/create`

### Parameters

| Name | In | Type | Required | Description |
| --- | --- | --- | --- | --- |
| `orgid` | header | string | yes | Organization (tenant) identifier. Every request is scoped to this org; data from other orgs is never visible. Issued with your API credentials. |
| `id` | path | string | yes | Chat message id. Omit to list all. |

### Responses

| Status | Meaning |
| --- | --- |
| `200` | Chat messages |
| `401` | customer is required — No signed-in customer or user could be resolved. |
| `403` | You do not have permission to perform this action — The caller is authenticated but lacks the role required by the endpoint, or is acting on another org. |
| `429` | Too Many Requests — More than 100,000 requests from one IP within 5 minutes (configurable per deployment). CORS preflights and requests from inside the platform cluster are not counted. The limiter answers before the error filter, so the body is `{ statusCode, error, message }` with no `path`, `method` or `timeStamp`; the `RateLimit-*` response headers say when the window resets. |
| `500` | An unexpected error occurred. Our team has been notified. — An unhandled server-side failure. |

## DELETE /crm/chat-message/delete/{id}

**Delete a chat message**

`operationId: CRMController_deleteChatMessage`

Deletes one of the caller's chat messages.

#### Signature

```http
DELETE /crm/chat-message/delete/{id} (id: string) -> Deletion result
```

#### Access

Requires a bearer JWT (`Authorization: Bearer <token>`).

#### Errors

| Status | Code | Message | When | What to do |
| --- | --- | --- | --- | --- |
| `401` | CUSTOMER_REQUIRED | customer is required | No signed-in customer or user could be resolved. | Sign in — these routes are scoped to the caller. |
| `400` | CUSTOMER_MISMATCH | customer does not match | The record belongs to a different customer than the caller. | You can only act on your own messages. |

Plus the standard platform errors: `403`, `429`, `500`.

#### See also

- `POST /crm/chat-message/update`

### Parameters

| Name | In | Type | Required | Description |
| --- | --- | --- | --- | --- |
| `orgid` | header | string | yes | Organization (tenant) identifier. Every request is scoped to this org; data from other orgs is never visible. Issued with your API credentials. |
| `id` | path | string | yes | Chat message id. |

### Responses

| Status | Meaning |
| --- | --- |
| `200` | Deletion result |
| `400` | customer does not match — The record belongs to a different customer than the caller. |
| `401` | customer is required — No signed-in customer or user could be resolved. |
| `403` | You do not have permission to perform this action — The caller is authenticated but lacks the role required by the endpoint, or is acting on another org. |
| `429` | Too Many Requests — More than 100,000 requests from one IP within 5 minutes (configurable per deployment). CORS preflights and requests from inside the platform cluster are not counted. The limiter answers before the error filter, so the body is `{ statusCode, error, message }` with no `path`, `method` or `timeStamp`; the `RateLimit-*` response headers say when the window resets. |
| `500` | An unexpected error occurred. Our team has been notified. — An unhandled server-side failure. |

## POST /crm/chat-message/create

**Create a chat message**

`operationId: CRMController_createChatMessage`

Posts a new chat message on behalf of the caller.

#### Signature

```http
POST /crm/chat-message/create (body) -> The created chat message
```

#### Access

Requires a bearer JWT (`Authorization: Bearer <token>`).

#### Errors

| Status | Code | Message | When | What to do |
| --- | --- | --- | --- | --- |
| `401` | CUSTOMER_REQUIRED | customer is required | No signed-in customer or user could be resolved. | Sign in — these routes are scoped to the caller. |

Plus the standard platform errors: `403`, `429`, `500`.

#### See also

- `POST /crm/chat-message/update`

### Parameters

| Name | In | Type | Required | Description |
| --- | --- | --- | --- | --- |
| `orgid` | header | string | yes | Organization (tenant) identifier. Every request is scoped to this org; data from other orgs is never visible. Issued with your API credentials. |

### Request body

The message to create.

```json
{
  "data": {
    "body": "Hello, I have a question about my order",
    "channel": "chat"
  }
}
```

### Responses

| Status | Meaning |
| --- | --- |
| `201` | The created chat message |
| `401` | customer is required — No signed-in customer or user could be resolved. |
| `403` | You do not have permission to perform this action — The caller is authenticated but lacks the role required by the endpoint, or is acting on another org. |
| `429` | Too Many Requests — More than 100,000 requests from one IP within 5 minutes (configurable per deployment). CORS preflights and requests from inside the platform cluster are not counted. The limiter answers before the error filter, so the body is `{ statusCode, error, message }` with no `path`, `method` or `timeStamp`; the `RateLimit-*` response headers say when the window resets. |
| `500` | An unexpected error occurred. Our team has been notified. — An unhandled server-side failure. |

## POST /crm/chat-message/update

**Update a chat message**

`operationId: CRMController_updateChatMesssage`

Updates an existing chat message belonging to the caller.

#### Signature

```http
POST /crm/chat-message/update (body) -> The updated chat message
```

#### Access

Requires a bearer JWT (`Authorization: Bearer <token>`).

#### Errors

| Status | Code | Message | When | What to do |
| --- | --- | --- | --- | --- |
| `401` | CUSTOMER_REQUIRED | customer is required | No signed-in customer or user could be resolved. | Sign in — these routes are scoped to the caller. |
| `400` | CUSTOMER_MISMATCH | customer does not match | The record belongs to a different customer than the caller. | You can only act on your own messages. |

Plus the standard platform errors: `403`, `429`, `500`.

#### See also

- `DELETE /crm/chat-message/delete/{id}`

### Parameters

| Name | In | Type | Required | Description |
| --- | --- | --- | --- | --- |
| `orgid` | header | string | yes | Organization (tenant) identifier. Every request is scoped to this org; data from other orgs is never visible. Issued with your API credentials. |

### Request body

The message to update. Include its `sk`.

```json
{
  "sk": "66f1a2b3c4d5e6f708192a3b",
  "data": {
    "body": "Corrected text"
  }
}
```

### Responses

| Status | Meaning |
| --- | --- |
| `201` | The updated chat message |
| `400` | customer does not match — The record belongs to a different customer than the caller. |
| `401` | customer is required — No signed-in customer or user could be resolved. |
| `403` | You do not have permission to perform this action — The caller is authenticated but lacks the role required by the endpoint, or is acting on another org. |
| `429` | Too Many Requests — More than 100,000 requests from one IP within 5 minutes (configurable per deployment). CORS preflights and requests from inside the platform cluster are not counted. The limiter answers before the error filter, so the body is `{ statusCode, error, message }` with no `path`, `method` or `timeStamp`; the `RateLimit-*` response headers say when the window resets. |
| `500` | An unexpected error occurred. Our team has been notified. — An unhandled server-side failure. |

