Rillo API
Your book, in the tools you already use.
Let your AI assistant or your automations read your Rillo book and leave notes, tasks and drafts in it.
- MCP server
- HTTPS API
- Signed webhooks
What it does
The Rillo API is a key your company makes in Rillo. With it, an AI assistant or another tool can search your people and companies, open a record, see today's follow-ups and search Rillo's answers. It can also add a note or a task to a record, and draft a follow-up.
Nothing sends a message from outside Rillo. A drafted follow-up waits in Rillo under Waiting for your yes, and only a person in Rillo sends it. Notes and tasks land on the record the next time the person who made the key has Rillo open.
There are two ways in, with the same tools behind both: the MCP server, for AI assistants, and the HTTPS API, for code and automations. Webhooks tell your tools when something happens in Rillo.
Use it from your AI assistant
Rillo runs an MCP server, the standard way AI assistants reach other tools. Its address is https://rilloapp.com/api/mcp. It uses the Streamable HTTP transport and answers each request on its own, and it signs you in with your key: Authorization: Bearer and the key. Rillo does not offer OAuth sign-in yet, so an assistant has to let you add that header.
What your assistant can do
search_bookUp to 20 matching people and companies, each with its record id.Read the bookget_recordThe record: contact details, stage, deal value, the latest notes, open tasks, follow-ups and drafts waiting.Read the booktodays_movesFor the person who made the key: what is overdue and due today, who to call and why, and the deals gone quiet.Read the bookadd_noteThe note, staged on the record and marked as written through this key.Write notes and tasks, changes Rilloadd_taskThe task, staged on the record and marked as made through this key.Write notes and tasks, changes Rillodraft_follow_upA draft that waits in Rillo under Waiting for your yes. It is never sent from here.Draft messages, changes Rillosearch_answersThe best matches from Rillo's answers library, each with a short answer and its steps.Search answersAn assistant only sees the tools your key's permissions allow.
Set it up
- Claude (claude.ai, the desktop app and Cowork): Customize, then Connectors, then Add custom connector. Paste
https://rilloapp.com/api/mcp, and under Request headers addAuthorizationwith the valueBearerand your key. - Claude Code, in a terminal:
In a sharedclaude mcp add --transport http rillo https://rilloapp.com/api/mcp \ --header "Authorization: Bearer rillo_k_YOUR_KEY_GOES_HERE".mcp.json, write the key as${RILLO_KEY}so it never lands in the file. - Gemini CLI:
gemini mcp add --transport http \ --header "Authorization: Bearer rillo_k_YOUR_KEY_GOES_HERE" \ rillo https://rilloapp.com/api/mcp - ChatGPT cannot add this server with a key. Use the HTTPS API instead: in a custom GPT's Actions, import
https://rilloapp.com/api/v1/openapi.jsonand set Authentication to API key, Bearer. - The Gemini app and Gemini for Workspace need OAuth sign-in, which Rillo does not offer yet.
Supported MCP protocol versions: 2025-11-25, 2025-06-18, 2025-03-26, 2024-11-05.
The web API
The same tools, as plain HTTPS, with the same key, permissions and limits. Each tool is POST https://rilloapp.com/api/v1/<tool>: the JSON body is the tool's arguments and the answer is its result.
search_bookquery (words: a name, a company, an email, a phone or a stage), limit 1 to 20Up to 20 matching people and companies, each with its record id.get_recordid (from search_book)The record: contact details, stage, deal value, the latest notes, open tasks, follow-ups and drafts waiting.todays_movesNothingFor the person who made the key: what is overdue and due today, who to call and why, and the deals gone quiet.add_noteid, note (up to 2,000 characters)The note, staged on the record and marked as written through this key.add_taskid, title, and due as YYYY-MM-DD if it has a dayThe task, staged on the record and marked as made through this key.draft_follow_upid, channel (email or text), subject, bodyA draft that waits in Rillo under Waiting for your yes. It is never sent from here.search_answersquery (a question in plain words)The best matches from Rillo's answers library, each with a short answer and its steps.An example
Search the book for a name. The key below is a placeholder: use your own.
curl -X POST https://rilloapp.com/api/v1/search_book \
-H "Authorization: Bearer rillo_k_YOUR_KEY_GOES_HERE" \
-H "Content-Type: application/json" \
-d '{"query": "McLaughlin", "limit": 5}'
The rest of the API
GET /api/v1/openapi.jsonThe OpenAPI 3.1 description. Public, and holds no data.GET /api/v1/meYour company, the key's name, who made it and its permissions.POST /api/v1/hooksSubscribe a webhook (below).DELETE /api/v1/hooks?id=<id>Remove a webhook this key made.GET /api/v1/events?type=<type>The latest five events of one type, for a sample or for polling.Errors come back as { "error", "message" }: 400 for bad arguments, 401 for a missing or revoked key, 403 for a permission the key does not have, 422 when Rillo could not do it (the message says why), 429 for too many calls (with retry-after), and 503 while the API is still being set up for your Rillo.
Zapier and Make
Rillo's own Zapier and Make apps are not in their directories yet. Today you connect them with the pieces above: a webhook to start a Zap or a scenario when something happens in Rillo (Webhooks by Zapier, or Make's custom webhook), and the HTTPS API with your key to search the book or leave a note, a task or a draft.
Webhooks
A webhook sends an event to your address the moment it happens. These are the ones made for the API, and the rest of Rillo's automation events can be chosen too:
lead.createdA new lead.deal.stage_changedA deal moves stage.booking.madeA booking is made.quote.signedA quote is accepted.payment.paidA Rillo Pay payment is paid.workflow.ranA workflow runs.Only owners, admins and managers set them, because a webhook carries the whole company's events. They set one in Settings, or through POST /api/v1/hooks with a key they made: { "url": "https://...", "events": ["booking.made"], "app": "zapier" }. A webhook made with a key stops when the key is revoked, or when the person who made it no longer holds one of those roles.
Each delivery is a JSON body, { id, type, version, occurred_at, data }, signed with the webhook's secret:
x-rillo-signature: t=1767225600,v1=<hex HMAC-SHA256 of "t.body", keyed with the webhook's secret>
Check the signature, and reject a delivery whose t is more than 300 seconds old. A failed delivery is tried again after 2, 4, 8 minutes and so on, up to 6 hours apart; after the eighth try it stops. Settings shows each delivery, and any one can be sent again. Addresses must be public https.
Keys
An owner or admin makes a key in Rillo, in Settings, Connect Rillo to your AI. They name it and pick what it may do:
book.readsearch_book, get_record, todays_movesnotes.writeadd_note, add_taskdrafts.writedraft_follow_upanswers.readsearch_answers- A key reads
rillo_k_and 43 more characters. Rillo shows it once, when it is made, and keeps only a hash of it. Copy it then. - A key acts as the person who made it, with the role they hold now, read again on every call. An owner, admin or manager sees every shared record in the company, a team lead their team's, anyone else their own. A key never sees another company, and writes only to records in its maker's own book.
- Revoke a key in the same place and it stops at once, with any webhooks made with it. If the person who made it leaves the company, it stops too.
- Up to 20 live keys a company.
If Connect Rillo to your AI says Being set up, the API is not on for your Rillo yet: every call answers 503 until it is.
Which plans include it
There is no separate API plan and no price per call. Making a key is part of your Rillo workspace's Settings, for its owners and admins. What a key can read and write is what the person who made it can, in the products your workspace has. See pricing for the plans themselves.
Limits, security and help
- Limits. 60 calls a minute and 1,000 an hour for each key, and 120 a minute from any one address. Past a limit the answer is 429 with
retry-after. A search returns at most 20 records. - What is logged. Every call that passes the key is logged with the key, the person, the tool and the time, never what was sent. Owners and admins see the latest calls in Settings.
- What a key cannot do. Send an email or a text, delete a record, or see another company.
- Keep it secret. Treat a key like a password: keep it out of shared files and code, and revoke it if it gets out.
- Something not working? Write to Rillo support with the key's name (never the key) and what you called.
Help with the Rillo API
support@rilloapp.comSay which key (its name, never the key itself), what you called and what came back.
Which one are you?
One login, one record: the card you hand someone, the list at your counter and the accounts your reps carry are the same record.
I want to meet people
Free, forever
Rillo
The company behind Connect
Scan to open this card. Tap to close.
Your card, your Rillodex, and a CRM when you want one. Write to us any time.
Hand over your card, they scan it, and you are in their phone. Everyone you meet lands in your Rillodex.
Rillo Connect about a minuteI run a shop
From $79 a month
Getting found. 5 areas checked.
We check your Google listing, build your pages and ask for reviews, so customers can find you. A regulars list builds itself at the counter.
Rillo Shops set up with youI run a sales team
From $49 a seat
Built this morning from what's overdue and gone quiet.
Talk after a call and Rillo writes the record and sets the follow-up. Built for the phone first, and just as good at the desk.
Rillo CRM 30 days free