Prepare the endpoint
Provide a public HTTPS endpoint that acceptsPOST requests with JSON and a
client-issued, read-only API key in Authorization: Bearer <api-key>.
Use a URL without credentials, a query string, or a fragment. Redirects and
private-network addresses are refused. The endpoint must resolve to public IPv4.
Each request contains up to 200 users from the same App and environment:
customer_id is the exact, case-sensitive customer reference supplied to FloKit
by the accepted payment trial event (identity.userRef). Confirm that your
endpoint maps that reference to the correct App account. Do not match by email
or assume a payment provider’s customer ID is the same reference.
FloKit retains the reference for new accepted payment trials while the lookup
is enabled. Existing trials without a retained reference use the approved
generic email. Enabling the connection does not populate historical trials.
Return activity facts
Return HTTP200, Content-Type: application/json, and no compressed response.
Return only the fields below; do not include raw events, profile data, health
information, or additional attributes.
For
unknown_customer or unavailable, return only customer_id and status:
data_as_of; coverage cannot precede the requested trial start. A customer who
has never opened the App cannot already be activated or have a last activity
timestamp. Activation in the requested trial requires a known last activity
within that trial window. An omitted requested customer uses generic copy.
Do not return unrequested customers or duplicate references.
The maximum response is 1 MiB. Each attempt has a ten-second timeout, with
at most one immediate retry for a transient failure. Authentication, validation,
rate-limit responses, and redirects are not immediately retried. Activity
decisions may be cached for fifteen minutes; coverage older than one hour uses
generic copy.
How the email is chosen
A missing or unapproved generic template blocks delivery. Current consent,
conversion, suppression, email mode, pause, campaign rules, sender readiness,
send timing, and frequency limits still apply. A skipped nudge is not counted
as an email sent. A retry after possible provider submission retains the same
email content.
Configure FloKit
- Select the correct App. These settings apply to the production environment. Open Governance → Marketing emails → Campaign rules → Trial not converted: App activity lookup.
- Enter the endpoint URL and API key. Never paste the key into a chat or support message. Saved keys are write-only; leave the key blank to retain the saved key.
- Confirm the exact customer-reference mapping.
- Review and approve the three content variants. Confirm the App’s approved generic trial-value template, public App destination, business mailing address, and sending identity are configured.
- Enable the lookup and select Save lookup. Saving changes the lookup only; email mode, pause, campaign switches, and schedules are separate controls.
- Select Test saved connection. The test authenticates against the saved
endpoint with exactly
{"users":[]}and expects a valid envelope with a freshdata_as_ofand"users":[]. No customers are queried and no email is sent.
Troubleshooting
See branded email setup for sender verification.