# FYInbox developer documentation

Send project activity to one inbox for people and agents. Use a source API key from a trusted server or automation runtime.

- [Quickstart](https://fyinbox.com/docs/quickstart): Move one project notification out of chat and into FYInbox for people and agents with a source API key and a single HTTP request.
- [Concepts](https://fyinbox.com/docs/concepts): Understand the small set of account, source, notification, tag, metadata, action, and push concepts used by the product.
- [API authentication](https://fyinbox.com/docs/authentication): Authenticate producer and agent requests with a source-scoped bearer key while keeping the secret out of clients, payloads, logs, and source control.
- [Notification payload](https://fyinbox.com/docs/notification-payload): Start with a title, then add severity, body, tags, metadata, event identity, timestamp, and safe link actions only when useful.
- [Deduplication and retries](https://fyinbox.com/docs/deduplication): Give each logical event a stable source-scoped key so a network retry cannot create a second inbox item while the original is retained.
- [FYInbox TypeScript SDK](https://fyinbox.com/docs/typescript-sdk): Use the server-only TypeScript client for runtime validation, bounded responses, safe errors, deadlines, and conservative retry behavior.
- [Connect an MCP client](https://fyinbox.com/docs/mcp): Connect agents to FYInbox with Streamable HTTP and a source key to report project outcomes and inspect known notifications in the inbox for people and agents.
- [Errors and retries](https://fyinbox.com/docs/errors-and-retries): Branch on HTTP status and stable error code, preserve unknown codes, honor Retry-After, and avoid replaying ambiguous non-idempotent mutations.
- [Limits](https://fyinbox.com/docs/limits): Design producers below the public protocol ceilings and expect the running deployment or account policy to enforce lower operational values.
- [API reference](https://fyinbox.com/docs/api-reference): Use the versioned API for notification creation, agent-readable notification context, and scoped metadata mutation; dashboard and account endpoints are not public APIs.
- [Security and privacy](https://fyinbox.com/docs/security-and-privacy): Minimize notification data, keep producer credentials server-side, and understand what the managed service must decrypt to provide inbox and filtering features.
- [Compatibility policy](https://fyinbox.com/docs/compatibility): Integrate against the versioned contract, accept additive response evolution, and use stable error codes and schemas instead of dashboard internals.
- [Changelog](https://fyinbox.com/docs/changelog): Track public producer API, machine-contract, SDK, and documentation changes without mixing in private dashboard implementation details.

- [OpenAPI 3.1](https://fyinbox.com/openapi.json)
- [API catalog](https://fyinbox.com/.well-known/api-catalog)
- [Agent Skills](https://fyinbox.com/.well-known/agent-skills/index.json)
- [MCP server card](https://fyinbox.com/.well-known/mcp/server-card.json)
