> ## Documentation Index
> Fetch the complete documentation index at: https://docs.neuraldraft.io/llms.txt
> Use this file to discover all available pages before exploring further.

# Subscribe to a project newsletter

> **Public** endpoint — no API key required when called from a browser
embed. The project is resolved via the
`X-NeuralDraft-Project-Key` header (recommended for server-side calls)
or `?project_id=<id>` query param (browser embeds where you can't
ship a secret key). Idempotent — re-submitting an existing email
returns 200 with `status="already_subscribed"` rather than an error.
Free; no credits charged.




## OpenAPI

````yaml /openapi.yaml post /newsletters/subscribe
openapi: 3.1.0
info:
  title: Neural Draft Project API
  version: 1.0.1
  summary: The AI-native backend platform for Lovable / Claude / v0 / Bolt-built sites.
  description: |
    The **Neural Draft Project API** is the single REST contract every AI-built
    site, MCP server tool call, and SDK in our ecosystem speaks against. One
    project key (`ndsk_live_...`) gets you CMS, blog, social, booking and
    commerce primitives behind a stable v1 surface.

    ## Quick start

    ```bash
    curl https://api.neuraldraft.io/v1/projects/me \
      -H "Authorization: Bearer ndsk_live_yourkey"
    ```

    ## Authentication

    Every endpoint except `GET /health` requires a project API key passed as
    `Authorization: Bearer ndsk_live_...`. Keys are scoped to a single project
    (formerly "tenant"). Resolve the project context by calling
    `GET /projects/me`.

    Keys carry one or more **scopes** (e.g. `content:write`, `commerce:admin`).
    A `403 Forbidden` is returned if the key lacks the scope required by the
    endpoint.

    ## Credits

    Most operations cost credits. Costs are documented per endpoint in this
    spec and on the [pricing page](https://neuraldraft.io/pricing). When a
    project has no credits left, every credit-consuming operation returns
    `402 Payment Required` with `code: insufficient_credits`. The response
    includes `cost` (credits the operation needed) and `balance` (credits the
    project had on hand) so clients can render an exact top-up prompt.

    Read-only endpoints (`GET`) do not consume credits. Mutating writes —
    upserting a content key, creating or updating a page, registering an
    image (URL swap or multipart upload) — cost **1 credit** each on top of
    the AI-generation costs documented per endpoint.

    ## Rate limits

    Default project budget is **60 requests per minute**, burst **120**. Every
    response includes:

    | Header | Meaning |
    |---|---|
    | `X-RateLimit-Limit` | Window ceiling |
    | `X-RateLimit-Remaining` | Requests left in window |
    | `X-RateLimit-Reset` | Unix seconds when bucket refills |
    | `Retry-After` | Seconds to wait, only on `429` |

    Enterprise plans get higher budgets — contact sales.

    ## Async work

    Long-running operations (blog generation, image generation, batch
    translation, content plans, full website generation) return a
    [`Job`](#tag/Jobs) resource immediately with `202 Accepted` and
    `status: pending`. Two ways to track progress:

    1. **Poll** `GET /jobs/{id}` until `status` is one of `completed`,
       `failed` or `cancelled`.
    2. **Stream** `GET /jobs/{id}/stream` for a Server-Sent Events feed of
       `progress`, `step`, `done`, `error` events.

    ## Webhooks

    Outgoing webhooks let your project URL receive events (e.g.
    `order.paid`, `blog_post.published`). Manage delivery URLs at
    [`/webhook-endpoints`](#tag/Webhooks). Every delivery is signed with
    HMAC-SHA256:

    ```
    X-Neural-Draft-Signature: t=1745000000,v1=<hex_hmac_sha256(body, secret)>
    X-Neural-Draft-Event: order.paid
    X-Neural-Draft-Delivery: <uuid>
    ```

    Verify the timestamp is within 5 minutes and the HMAC matches before
    trusting the payload.

    ## Idempotency

    Mutating endpoints accept an `Idempotency-Key` header (any unique string
    up to 255 chars). Retries with the same key within 24 hours return the
    original response without re-executing the side effect.

    ## Errors

    All errors follow [RFC 7807](https://datatracker.ietf.org/doc/html/rfc7807)
    `application/problem+json` shape. The `code` field is a stable machine
    identifier; the `detail` is a human-readable explanation.
  termsOfService: https://neuraldraft.io/legal/terms
  contact:
    name: Neural Draft Support
    email: info@neuraldraft.io
    url: https://neuraldraft.io/support
  license:
    name: Proprietary
    url: https://neuraldraft.io/legal/api-license
  x-logo:
    url: https://neuraldraft.io/assets/logo-dark.svg
    altText: Neural Draft
servers:
  - url: https://api.neuraldraft.io/v1
    description: Production
  - url: https://api.staging.neuraldraft.io/v1
    description: Staging
security:
  - apiKeyAuth: []
tags:
  - name: Health
    description: Liveness, version, and the runtime OpenAPI document.
  - name: Projects
    description: >
      Project (formerly "tenant") metadata, API key management, and credit
      usage.

      Every API key resolves to exactly one project.
  - name: Brand
    description: |
      Canonical brand context — voice, colors, fonts, audience, content tone.
      This is the single source of truth that the MCP server's `brand://current`
      resource exposes to AI codegen tools.
  - name: Content
    description: |
      The CMS pillar. Translation keys map `dot.notation` keys to per-language
      values. Use `bulk` for build-time fetches of many keys at once.
  - name: Components
    description: >
      Editable HTML chunks registered by AI codegen tools during a build
      session.

      A registered component becomes editable in the project's admin UI.
  - name: Pages
    description: |
      Multi-page authoring with per-page SEO meta (meta_title, meta_description,
      og_*, canonical_url). Pages live alongside the components that render
      them.
  - name: Galleries
    description: |
      Named, ordered image collections. One `slug` per gallery, an `items`
      array of `{url, alt}` (max 200). Updates are full-replace — fetch,
      mutate, send the complete new list back. Use for carousels, lookbooks,
      product galleries, and any other variable-length image set.
  - name: Images
    description: Brand-consistent image generation, replacement, and resolution by key.
  - name: Blog
    description: |
      Full blog engine — posts, categories, tags, scheduling, multi-language
      translation, AI authoring pipeline.
  - name: Social
    description: |
      Social pillar — multi-platform post generation, scheduling, publishing,
      OAuth account connections.
  - name: Booking
    description: |
      Booking pillar — bookable services, weekly availability, slot lookup,
      bookings (admin + public), embeddable widget.
  - name: Commerce
    description: |
      Commerce pillar — products, variants, categories, orders, Stripe
      Checkout, Stripe Connect onboarding, embeddable widgets.
  - name: Jobs
    description: |
      Async work tracking. Every long-running AI op (blog gen, image gen,
      translation, content plan, website gen) returns a Job. Poll or stream.
  - name: Webhooks
    description: |
      Outgoing webhooks. Subscribe a URL to events your project cares about.
      All deliveries signed with HMAC-SHA256.
  - name: Forms
    description: |
      Lead-capture surfaces — newsletter subscribe and contact-form submit.
      Public submit endpoints (no auth, project resolved via
      `X-NeuralDraft-Project-Key` or `?project_id=`); admin list/delete
      endpoints require an API key with `forms:read` / `forms:write` scope.
      No credits charged — this is storage + delivery, not AI.
paths:
  /newsletters/subscribe:
    post:
      tags:
        - Forms
      summary: Subscribe to a project newsletter
      description: |
        **Public** endpoint — no API key required when called from a browser
        embed. The project is resolved via the
        `X-NeuralDraft-Project-Key` header (recommended for server-side calls)
        or `?project_id=<id>` query param (browser embeds where you can't
        ship a secret key). Idempotent — re-submitting an existing email
        returns 200 with `status="already_subscribed"` rather than an error.
        Free; no credits charged.
      operationId: subscribeNewsletter
      parameters:
        - in: header
          name: X-NeuralDraft-Project-Key
          schema:
            type: string
          required: false
          description: Project API key (alternative to query param).
        - in: query
          name: project_id
          schema:
            type: integer
          required: false
          description: Project ID for unauthenticated browser embeds.
      requestBody:
        required: true
        content:
          application/json:
            schema:
              type: object
              required:
                - email
              properties:
                email:
                  type: string
                  format: email
                  maxLength: 255
                app_lead:
                  type: boolean
                  default: false
                  description: >-
                    Marks the lead as coming from a "want the app" landing
                    surface vs. a regular newsletter signup.
            examples:
              basic:
                value:
                  email: jane@example.com
              app_lead:
                value:
                  email: jane@example.com
                  app_lead: true
      responses:
        '200':
          description: Email already subscribed (idempotent).
          content:
            application/json:
              schema:
                type: object
                properties:
                  data:
                    $ref: '#/components/schemas/NewsletterSubscription'
        '201':
          description: New subscription created.
          content:
            application/json:
              schema:
                type: object
                properties:
                  data:
                    $ref: '#/components/schemas/NewsletterSubscription'
        '403':
          $ref: '#/components/responses/Forbidden'
        '422':
          $ref: '#/components/responses/UnprocessableEntity'
        '429':
          $ref: '#/components/responses/TooManyRequests'
      security: []
components:
  schemas:
    NewsletterSubscription:
      type: object
      required:
        - id
        - email
      properties:
        id:
          type: integer
          example: 42
        email:
          type: string
          format: email
          example: jane@example.com
        app_lead:
          type: boolean
          example: false
        status:
          type: string
          enum:
            - subscribed
            - already_subscribed
          description: Only present on the public submit endpoint.
        subscribed_at:
          type:
            - string
            - 'null'
          format: date-time
    Error:
      type: object
      description: |
        RFC 7807 problem+json error. The `code` is a stable machine
        identifier; clients should branch on `code`, never on `title`.
      required:
        - type
        - title
        - status
        - code
      properties:
        type:
          type: string
          format: uri
          example: https://api.neuraldraft.io/errors/validation_failed
        title:
          type: string
          example: Validation failed
        status:
          type: integer
          example: 422
        detail:
          type: string
          example: One or more fields failed validation.
        instance:
          type: string
          description: Request id (also returned as `X-Request-Id` header).
          example: req_2Nh4PqRsTuVw
        code:
          type: string
          description: |
            Stable machine error code. Standard values:
            `bad_request`, `unauthorized`, `insufficient_credits`,
            `forbidden`, `not_found`, `conflict`, `validation_failed`,
            `rate_limited`, `internal_error`, `service_unavailable`,
            `slot_unavailable`, `connect_not_ready`, `upstream_unavailable`,
            `idempotency_conflict`.
          example: validation_failed
        cost:
          type: integer
          description: |
            Credits the operation requires. Only present on
            `402 insufficient_credits` responses.
          example: 1
        balance:
          type: integer
          description: |
            Credits the project had on hand at the time of the request.
            Only present on `402 insufficient_credits` responses.
          example: 0
        errors:
          type: object
          description: Field-level validation errors (only on 422).
          additionalProperties:
            type: array
            items:
              type: string
          example:
            customer_email:
              - The customer email field must be a valid email.
            starts_at:
              - The starts at field must be a valid ISO 8601 date.
  responses:
    Forbidden:
      description: API key lacks required scope.
      headers:
        X-Request-Id:
          schema:
            type: string
      content:
        application/problem+json:
          schema:
            $ref: '#/components/schemas/Error'
          examples:
            scope:
              value:
                type: https://api.neuraldraft.io/errors/forbidden
                title: Forbidden
                status: 403
                detail: This API key does not have the `commerce:write` scope.
                code: forbidden
                instance: req_2Nh4PqRsTuVw
    UnprocessableEntity:
      description: Semantic validation failed (well-formed body, but field values invalid).
      headers:
        X-Request-Id:
          schema:
            type: string
      content:
        application/problem+json:
          schema:
            $ref: '#/components/schemas/Error'
          examples:
            invalid:
              value:
                type: https://api.neuraldraft.io/errors/validation_failed
                title: Validation failed
                status: 422
                detail: One or more fields failed validation.
                code: validation_failed
                instance: req_2Nh4PqRsTuVw
                errors:
                  customer_email:
                    - The customer email field must be a valid email address.
                  starts_at:
                    - The starts at field must be a date after now.
    TooManyRequests:
      description: |
        Rate limit hit. Project default is 60 req/min, burst 120. Wait
        `Retry-After` seconds and retry.
      headers:
        Retry-After:
          schema:
            type: integer
          description: Seconds to wait before retrying.
        X-RateLimit-Limit:
          schema:
            type: integer
        X-RateLimit-Remaining:
          schema:
            type: integer
        X-RateLimit-Reset:
          schema:
            type: integer
        X-Request-Id:
          schema:
            type: string
      content:
        application/problem+json:
          schema:
            $ref: '#/components/schemas/Error'
          examples:
            ratelimited:
              value:
                type: https://api.neuraldraft.io/errors/rate_limited
                title: Too many requests
                status: 429
                detail: Rate limit exceeded. Retry in 12 seconds.
                code: rate_limited
                instance: req_2Nh4PqRsTuVw
  securitySchemes:
    apiKeyAuth:
      type: http
      scheme: bearer
      bearerFormat: API Key
      description: |
        Project API key. Pass as `Authorization: Bearer ndsk_live_...`. Manage
        keys via [`/projects/me/api-keys`](#tag/Projects). Test-mode keys use
        the `ndsk_test_` prefix.

````