Push notifications

Push notifications

Register a device's APNs, FCM or browser push token, then send a push with one HTTPS request.

All endpoints live on https://app.nativenotify.com and take your app id and app token — in the body for POSTs, in the URL for GETs. A dashboard session or an MCP token can stand in for the app token on POSTs, for apps that account can access.

Kinds of push

KindAudienceUse for
Mass push{ "type": "all" } — every registered deviceAnnouncements to everyone.
Individual pushOne deviceId or one subscriberIdAccount alerts, like "your order shipped".
Group push{ "type": "group", "key": "…" }Everyone subscribed to a group.

All three share one response shape, one inbox entry per targeted device and the same analytics.

Endpoints

EndpointAuthDoes
POST /api/universal/device/registerbodyRegister a device and its APNs, FCM or webPush token. Idempotent.
POST /api/universal/device/deregisterbodyRemove a device. Idempotent.
POST /api/universal/notifications/sendbodySend to everyone, a device list, a subscriber list or a group.
POST /api/universal/test-sendbodySend to one device or token and return the result.
GET /api/universal/health/:appId/:appTokenURLDevice and token counts.
POST /api/universal/credentials/validatebodyCheck the stored FCM and APNs credentials.
GET /api/universal/web-push/keys/:appId/:appTokenURLThe app's VAPID public key.
POST /api/universal/groups/subscribe and /unsubscribebodyAdd or remove subscribers or devices in a group.
GET, POST /api/universal/environments/:appId/:appTokenURLList or switch environments.
GET /api/universal/inbox/:appId/:appToken?deviceId=URLOne device's inbox, with unread, read, read-all and delete actions.

Scheduling, AI copy and owner-side reads are account routes under /api/apps/:appId/…. They take a dashboard session or an MCP token, never the app token.

Concepts

  • deviceId is a stable key you choose per install. Registering it again updates the device. A token that arrives with a different deviceId moves to that device.
  • subscriberId ties devices to one of your users. Optional; one subscriber can have many devices.
  • Environments: a device is production unless registered as staging or development, and a send reaches only its own environment. See Environments.
  • Tokens: APNs for iOS, FCM for Android, webPush for browsers. A mismatched pair is 400 token_platform_mismatch.
  • Errors use { "error": { "code", "message", "field"? } } with stable codes like no_tokens_provided.
  • Delivery: APNs and FCM acknowledge a send immediately, and that is the strongest signal a native token gives. Responses say delivered: null instead of guessing. See Verify delivery.

Credentials required

Sends use your FCM v1 service-account JSON (Android) and APNs .p8 key (iOS). Google shut down the legacy FCM server key, so it isn't accepted. See Push credentials.

Next steps