Median

POST /messages

Updated Oct 1, 20262 minute read

Send a message

The first message creates the visitor and the conversation. The AI starts answering unless a person already holds the thread.

New user values overwrite old ones and omitted fields are not erased. Query strings are stripped from page URLs on arrival.

Part of Conversations.

Request body

application/json, required.

FieldTypeRequiredDescription
sessionstringYesThe visitor's session token.
bodystringYesThe message. Can be empty when the message carries attachments.
userobjectNoWho this is, shown to your team.
user.namestringNoCut to 80 characters.
user.emailstringNoCut to 320 characters.
user.avatarUrlstringNoAn HTTPS URL up to 512 characters. Anything else is dropped.
user.metadataobjectNoYour own facts about them: plan, seats, account age. The first 16 entries are kept, and keys and values are cut to 200 characters.
contextobjectNoThe visitor's browser, shown beside the thread.
context.timeZonestringNo
context.localestringNo
context.browserstringNo
context.osstringNo
context.device"desktop" | "tablet" | "mobile"No
context.screenstringNo
pageobjectNoWhere they wrote from. Kept on the conversation's first message.
page.urlstringYes
page.titlestringNo
page.referrerstringNo
attachmentsobject[]NoUp to 6 files, with ids from POST /uploads.
attachments[].idstringYes
attachments[].namestringYes

Responses

StatusDescription
200The conversation it landed in, and the message.
400invalid_json: the body is not a JSON object. invalid_request: a field is missing, has the wrong type, or is unknown, and the message names the allowed fields. invalid_session: the session is not 8 to 128 characters. empty_message: no body and no attachments. message_too_long: the body is over 4,000 characters. too_many_attachments: more than 6. attachment_missing: an id is not a file from POST /uploads. attachment_wrong_type: the file is HTML, XHTML, SVG or XSLT.
401missing_api_key: no bearer token. invalid_api_key: the key matches no organization or was revoked. publishable_key: a median_pk_ key was sent. An OAuth access token is refused here with invalid_api_key.
429The organization's API allowance for this class of request is used up. Wait the Retry-After header's seconds. Limits depend on the plan. See rate limits.

200 body

FieldTypeRequiredDescription
conversationIdstringYes
messageIdstringYes

Example response

{
  "conversationId": "js7...",
  "messageId": "jd2..."
}

Example request

curl -X POST https://api.median.sh/v1/messages \
  -H "Authorization: Bearer $MEDIAN_KEY" \
  -H "content-type: application/json" \
  -d '{"session":"user_42","body":"How do I export my data?","user":{"name":"Ada","email":"ada@example.com"}}'

Still need help?

    Esc