Data model
Contacts
A person you keep in touch with. Carries identity (name, nickname, email, phone), context (company, address, social links), and lifecycle fields (birthday, anniversary, last_contacted_at). Acts as the parent for notes, activities, and reminders.
contact200Fields
Per-field validation rules. Values that violate any constraint are rejected with 400 before they reach the database.
| Field | Type | Constraints |
|---|---|---|
| city | string | max length 120 |
| name | string | max length 200 |
| tags | tags | - |
| color | string | max length 24 |
string | max length 320 | |
| notes | string | max length 8000 |
| phone | string | max length 64 |
| gender | enum | enum male | female | other | unspecified |
| company | string | max length 200 |
| country | string | max length 120 |
url | - | |
| website | url | - |
| birthday | string | max length 32 |
| favorite | bool | - |
url | - | |
| nickname | string | max length 120 |
| pronouns | string | max length 32 |
| allergies | string | max length 600 |
| job_title | string | max length 200 |
| food_prefs | string | max length 600 |
| how_we_met | string | max length 1000 |
| anniversary | string | max length 32 |
| address_line | string | max length 200 |
| avatar_blob_id | string | max length 64 |
| secondary_email | string | max length 320 |
| secondary_phone | string | max length 64 |
| last_contacted_at | string | max length 32 |
| stay_in_touch_topic | string | max length 400 |
| stay_in_touch_frequency | enum | enum never | weekly | biweekly | monthly | quarterly | yearly |
Mutability
Which fields can you send, and when? Anything without a marker is server-managed - sending it isn't an error, it's silently ignored.
| Field | Create | Patch |
|---|---|---|
| city | ||
| name | ||
| tags | ||
| color | ||
| notes | ||
| phone | ||
| gender | ||
| company | ||
| country | ||
| website | ||
| birthday | ||
| favorite | ||
| nickname | ||
| pronouns | ||
| allergies | ||
| job_title | ||
| food_prefs | ||
| how_we_met | ||
| anniversary | ||
| address_line | ||
| avatar_blob_id | ||
| secondary_email | ||
| secondary_phone | ||
| last_contacted_at | ||
| stay_in_touch_topic | ||
| stay_in_touch_frequency |
Fields marked create-only but not patchable are immutable after creation. Server-managed fields include id, timestamps, ownership, and status.
Filtering & sorting
Combinable on list endpoints. Repeating a filter key produces an IN clause; prefixing a sort key with - reverses direction. Example: ?status=open&status=blocked&sort=-created_at.
Filter keys
data__namedata__emaildata__companydata__citydata__countrydata__favoritedata__tagsdata__genderdata__stay_in_touch_frequencystatusis_archivedowned_bySort keys
created_atupdated_atdata__namedata__companydata__last_contacted_atdata__birthdaydata__stay_in_touch_frequencyDefault: name
Endpoints
Each endpoint below lists its HTTP method, path, and the PAT scope it needs. Code samples cover curl, JavaScript, TypeScript, Python, Rust, Java, and WebSocket.
/xapi2/data/contactcontact:listList objects
Returns a paginated list of objects you can read. Default page size is 20; pass ?limit= to change (capped per type). Use ?after=<id> for keyset pagination on created_at-sorted lists, or ?offset= for offset paging.
curl -H "Authorization: Bearer pat_…" \"https://friendship-tracker.com/xapi2/data/contact?limit=20"
/xapi2/data/contact/{id}contact:readRead one
Returns the object by id. 404 if it does not exist or you cannot read it (the two cases are intentionally conflated).
curl -H "Authorization: Bearer pat_…" \https://friendship-tracker.com/xapi2/data/contact/OBJECT_ID
/xapi2/data/contactcontact:createCreate
Creates a new object. Body is a flat JSON dict of field values. Server-side fields (id, timestamps, ownership) are filled automatically; only fields listed below as creatable are read from the body.
curl -H "Authorization: Bearer pat_…" \-H "Content-Type: application/json" \-X POST https://friendship-tracker.com/xapi2/data/contact \-d '{"name": "…"}'
/xapi2/data/contact/{id}contact:updateUpdate
Partial update. Only fields included in the body are touched; everything else is preserved. Same allow-list as create, minus the fields that are immutable post-create.
curl -H "Authorization: Bearer pat_…" \-H "Content-Type: application/json" \-X PATCH https://friendship-tracker.com/xapi2/data/contact/OBJECT_ID \-d '{"name": "…"}'
/xapi2/data/contact/{id}contact:deleteDelete
Removes the object. It vanishes from every default list immediately and stops being returned by read / list.
curl -H "Authorization: Bearer pat_…" \-X DELETE https://friendship-tracker.com/xapi2/data/contact/OBJECT_ID
Use in CLI
The same endpoints are also exposed via the Friendship Tracker CLI. For scripts, CI, and bulk imports it's usually the faster path.
friendshipcli contact list --limit 5friendshipcli contact get <id>friendshipcli contact create --name "Hello"friendshipcli contact upsert --unique name --csv items.csvfriendshipcli contact schema # fields & limits
Full command reference, profiles, CSV import, auto-retry, NDJSON streaming → /docs/cli