Build on top of your links
Create branded links, generate QR codes and pull analytics from your own apps. Predictable REST endpoints, JSON everywhere, and webhooks for real-time events.
curl -X POST https://shortgo.io/api/v1/links \ -H "Authorization: Bearer $API_KEY" \ -H "Content-Type: application/json" \ -d '{"url":"https://example.com/launch","alias":"launch"}'
const res = await fetch("https://shortgo.io/api/v1/links", { method: "POST", headers: { Authorization: `Bearer ${API_KEY}`, "Content-Type": "application/json" }, body: JSON.stringify({ url: "https://example.com/launch" }), }); const { short_url } = await res.json();
import requests r = requests.post("https://shortgo.io/api/v1/links", headers={"Authorization": f"Bearer {API_KEY}"}, json={"url": "https://example.com/launch"}) print(r.json()["short_url"])
$ch = curl_init("https://shortgo.io/api/v1/links"); curl_setopt_array($ch, [ CURLOPT_POST => true, CURLOPT_RETURNTRANSFER => true, CURLOPT_HTTPHEADER => ["Authorization: Bearer $apiKey", "Content-Type: application/json"], CURLOPT_POSTFIELDS => json_encode(["url" => "https://example.com/launch"]), ]); $link = json_decode(curl_exec($ch), true);
Authentication
Create an API key in your dashboard and send it as a Bearer token in the Authorization header. Keys can be read-only or read/write and revoked at any time.
Rate limits
Limits depend on your plan (requests per minute). Every response includes X-RateLimit-Limit, X-RateLimit-Remaining and X-RateLimit-Reset headers; exceeding the limit returns 429.
Webhooks
Subscribe to link.created, link.clicked, link.deleted and overlay.response events. Payloads are signed with HMAC-SHA256 so you can verify they came from us.
Endpoints
Base URL
All requests and responses use JSON. Errors return an "error" message with a meaningful HTTP status code. List endpoints are paginated with page and per_page.
The full reference with request and response schemas is available in your dashboard.
| Method | Endpoint | Description |
|---|---|---|
| GET | /links | List links with search and filters |
| POST | /links | Create a short link |
| GET | /links/{id} | Retrieve a link |
| PATCH | /links/{id} | Update destination, alias or options |
| DELETE | /links/{id} | Delete a link |
| GET | /links/{id}/stats | Clicks, countries, devices and referrers |
| GET | /qr | List QR codes |
| POST | /qr | Create a dynamic QR code |
| GET | /domains | List your branded domains |
| GET | /campaigns | List campaigns |
| GET | /account | Current user and plan usage |
Verify webhook signatures
Each delivery includes X-ShortGo-Timestamp and X-ShortGo-Signature headers. The signature is sha256= followed by the hex HMAC-SHA256 of "timestamp.body" using your webhook secret. Compare it in constant time and reject old timestamps.
{
"event": "link.clicked",
"created_at": "2026-01-01T12:00:00Z",
"data": {
"link_id": 42,
"country": "DE",
"device": "mobile",
"referrer": "instagram.com"
}
}