Developer-first URL infrastructure

Build on the fastest URL stack.

Sign up, grab an API key, and shorten your first URL with one curl — under 2 minutes.

1Get your API key

Create a free account, open the Dashboard → API Keys, and click Generate Key. Your secret is shown once — store it safely.

Keys start with zipt_live_ (or zipt_test_ in sandbox). Pass it via the X-API-Key header on every request.

2Shorten your first URL

# 2 minutes. No SDK required. curl -X POST https://www.ziptsystems.com/api/v1/shorten \ -H "X-API-Key: zipt_live_xxxxxxxx" \ -H "Content-Type: application/json" \ -d '{"url": "https://example.com/very/long/url", "customSlug": "launch"}'
# Response { "success": true, "data": { "shortUrl": "https://www.zipt.io/launch", "shortCode": "launch", "longUrl": "https://example.com/very/long/url" } }

3Endpoints

Method Path Description
POST /api/v1/shorten Create a short URL
POST /api/v1/bulk-shorten Bulk create (max 50 URLs/request)
GET /api/v1/links List your short URLs
GET /api/v1/analytics/{shortCode} Click analytics for one of your links
GET /api/v1/key/info API key metadata + usage
GET /api/v1/domains List your custom domains
POST /api/v1/domains/verify Verify a custom domain (DNS check)
POST /api/v1/domains/delete Remove a custom domain
GET /api/v1/links/{code}/qr?format=png|svg QR code for a link (SVG on paid plans)
All endpoints require the X-API-Key header. Responses use { "success": true, "data": {...} }; errors use { "success": false, "error": "...", "code": "..." }.

Rate limits (per plan)

Plan Rate limits (per hour · per minute · per month)
Free 100 / hour · 10 / min · 1,000 / month
Starter 500 / hour · 30 / min · 10,000 / month
Pro 2,000 / hour · 120 / min · 100,000 / month
Enterprise 10,000 / hour · 500 / min · 2,000,000 / month
Tip: These limits match your plan's API allowance. On HTTP 429 you receive Retry-After + X-RateLimit-* headers — respect them for smooth backoff.

Error codes

Code HTTP Meaning
UNAUTHORIZED 401 Missing / invalid API key
RATE_LIMITED 429 Rate limit exceeded
LIMIT_REACHED 429 Monthly link quota reached (upgrade your plan)
URL_THREAT_BLOCKED 403 URL flagged by threat intelligence / Web Risk
FORBIDDEN 403 You don't own the requested resource
INVALID_URL / URL_REJECTED 400 URL failed validation / security checks
ALIAS_TAKEN 409 Custom slug already in use
PLAN_REQUIRED 403 Feature requires a paid plan (e.g. SVG QR, custom domains)

Webhooks

Subscribe to link.clicked events from Dashboard → Webhooks. Deliveries are signed with a per-webhook HMAC-SHA256 secret (X-Zipt-Signature), retried with exponential backoff, and dead-lettered on repeated failure. Note: link.created and link.deleted events are not yet emitted — only link.clicked is currently delivered.

More samples

PHP

$ch = curl_init('https://www.ziptsystems.com/api/v1/shorten'); curl_setopt_array($ch, [ CURLOPT_POST => true, CURLOPT_RETURNTRANSFER => true, CURLOPT_HTTPHEADER => ['X-API-Key: zipt_live_xxx', 'Content-Type: application/json'], CURLOPT_POSTFIELDS => json_encode(['url' => 'https://example.com']), ]); $res = json_decode(curl_exec($ch), true);

Python

import requests r = requests.post("https://www.ziptsystems.com/api/v1/shorten", headers={"X-API-Key": "zipt_live_xxx"}, json={"url": "https://example.com"}) short = r.json()["data"]["shortUrl"]

JavaScript

fetch("https://www.ziptsystems.com/api/v1/shorten", { method: "POST", headers: { "X-API-Key": "zipt_live_xxx", "Content-Type": "application/json" }, body: JSON.stringify({ url: "https://example.com" }) });