REST API
Base URL https://api.ikomment.com/v1. JSON everywhere; errors use the envelope
{ code, message, requestId } with codes like ik.comment.too_long.
Mutating POSTs accept an Idempotency-Key header. Cursor pagination uses opaque
tokens — never offsets.
Authentication
- Widget endpoints: open (rate limited, Turnstile-gated where enabled).
- Server integrations:
Authorization: Bearer ik_sk_live_…API key (scopes: read, write, moderate, admin). - Dashboard: session cookie (30-day sliding,
Domain=.ikomment.com).
Public / widget
GET /config/:siteKey
GET /threads/:siteKey?url=&title=
GET /threads/:id/comments?sort=newest|oldest|top&cursor=&limit=
POST /threads/:id/comments { body_md, parent_id?, author_name?, author_email?, form_issued_at, form_signature }
PATCH /comments/:id { body_md }
DELETE /comments/:id
POST /comments/:id/vote { value: 1 | -1 }
POST /comments/:id/react { emoji }
POST /comments/:id/report { reason: spam|abuse|off_topic|other, note? }
GET /comments/:id
GET /threads/:id/seo (bot-rendered HTML + JSON-LD, flag-gated) Site admin
GET/POST/PATCH/DELETE /sites GET/PATCH /sites/:id/settings GET/PATCH /sites/:id/flags POST /sites/:id/rotate-key GET/POST/DELETE /sites/:id/api-keys GET/POST/PATCH/DELETE /sites/:id/word-filters GET/PATCH /sites/:id/mail-templates/:key GET/POST/PATCH/DELETE /sites/:id/webhooks GET/POST /sites/:id/badges POST /sites/:id/badges/:commentId/award|remove GET /sites/:id/usage?days=30 POST /sites/:id/purge-cache
Moderation
GET /moderation/queue?site_id=&status=pending|approved|spam
POST /moderation/comments/:id/approve|spam|delete|pin
POST /moderation/batch { ids: [...], action }
GET /reports?site_id=&status=open
POST /reports/:id/resolve { action: approve|spam|delete|dismiss }
GET /audit?site_id=
GET /spam/health?site_id=
POST /spam/retrain?site_id= Users, data ops, billing, ops
GET /users/me PATCH /users/me GET /users/me/notifications GET/PATCH /users/me/preferences POST /notifications/optout/:token POST /imports (multipart) GET /imports/:id POST /exports GET /exports/:id/download POST /privacy/export POST /privacy/delete POST /billing/checkout|portal POST /webhooks/stripe GET /health /version /status