Returns one message from a conversation in the current organization. Visitor callers can fetch messages only from their own conversations. The response includes full message metadata such as edit flags, reply links, mentions, and timestamps. Authenticate with an organization API key sent in `X-API-Key` or as a Bearer token and carrying the exact `conversations:read` scope. API-key access also requires the Automation & API module (`automation_api`). Authorized dashboard sessions remain supported where the route already permits them. The request is isolated to the authenticated organization. Resource and site/project identifiers must belong to that organization; out-of-scope identifiers are not disclosed. Retry behavior: This read-only operation is safe to retry.
/api/conversations/{id}/messages/{messageId}Organization API key supplied as Authorization: Bearer convor_sk_....
In: header
application/json
application/json
application/json
application/json
application/json
application/json
application/json
application/json
application/json
{
"id": "7f1f4d83-0a0e-4f34-9c4b-9a98d6e1c2ab",
"orgId": "8a8f4d83-0a0e-4f34-9c4b-9a98d6e1c2ab",
"conversationId": "9f1f4d83-0a0e-4f34-9c4b-9a98d6e1c2ab",
"senderType": "operator",
"senderId": "550e8400-e29b-41d4-a716-446655440000",
"content": "Your refund was approved today.",
"type": "text",
"metadata": {},
"isRead": true,
"isEdited": false,
"editedAt": null,
"createdAt": "2026-06-23T08:00:00.000Z",
"deletedAt": null,
"replyToId": null,
"mentions": [],
"searchVector": "'approv':4 'refund':2 'today':5"
}{
"error": {
"code": "string",
"message": "string",
"fields": {
"property1": "string",
"property2": "string"
},
"details": {},
"correlationId": "string"
}
}{
"error": {
"code": "string",
"message": "string",
"fields": {
"property1": "string",
"property2": "string"
},
"details": {},
"correlationId": "string"
}
}{
"error": {
"code": "string",
"message": "string",
"fields": {
"property1": "string",
"property2": "string"
},
"details": {},
"correlationId": "string"
}
}{
"error": {
"code": "string",
"message": "string",
"fields": {
"property1": "string",
"property2": "string"
},
"details": {},
"correlationId": "string"
}
}{
"error": {
"code": "string",
"message": "string",
"fields": {
"property1": "string",
"property2": "string"
},
"details": {},
"correlationId": "string"
}
}{
"error": {
"code": "string",
"message": "string",
"fields": {
"property1": "string",
"property2": "string"
},
"details": {},
"correlationId": "string"
}
}{
"error": {
"code": "string",
"message": "string",
"fields": {
"property1": "string",
"property2": "string"
},
"details": {},
"correlationId": "string"
}
}{
"error": {
"code": "string",
"message": "string",
"fields": {
"property1": "string",
"property2": "string"
},
"details": {},
"correlationId": "string"
}
}curl --request GET \
'https://api.convor.io/api/conversations/11111111-1111-4111-8111-111111111111/messages/33333333-3333-4333-8333-333333333333' \
--header 'Accept: application/json' \
--header 'Authorization: Bearer convor_sk_...'const response = await fetch("https://api.convor.io/api/conversations/11111111-1111-4111-8111-111111111111/messages/33333333-3333-4333-8333-333333333333", {
method: "GET",
headers: {
"Accept": "application/json",
"Authorization": "Bearer convor_sk_..."
},
});
const contentType = response.headers.get("content-type") ?? "";
const data = response.status === 204
? null
: contentType.includes("json")
? await response.json()
: contentType.startsWith("text/")
? await response.text()
: await response.blob();
if (!response.ok) {
const message = typeof data === "object" && data !== null
&& "error" in data && typeof data.error === "object"
&& data.error !== null && "message" in data.error
? String(data.error.message)
: "Convor API request failed (" + response.status + ")";
throw new Error(message);
}
console.log(data);Was this page helpful?
Edit a message
Updates the content of one non-deleted message and returns the full message. Edits are allowed only during the 5-minute grace period after message creation. Visitor callers can access only their own conversations and can edit only visitor messages they authored. The endpoint sanitizes the content, preserves up to 20 prior versions in edit history, refreshes search indexing, publishes a `message_edited` realtime event, and fires a `message.updated` webhook. Authenticate with an organization API key sent in `X-API-Key` or as a Bearer token and carrying the exact `conversations:write` scope. API-key access also requires the Automation & API module (`automation_api`). Authorized dashboard sessions remain supported where the route already permits them. The request is isolated to the authenticated organization. Resource and site/project identifiers must belong to that organization; out-of-scope identifiers are not disclosed. Editing records a revision and publishes the route's documented realtime update; callers should not assume that repeating an edit creates no additional revision metadata. Retry behavior: Repeating the same request converges on the same resource state, but a retry may return a conflict or not-found response after the first request succeeds.
List internal notes for a conversation
Returns up to 200 internal notes for one conversation in the current organization, ordered from newest to oldest. Internal notes are available only to authenticated operator sessions or scoped organization API keys and are never exposed to visitors. Each note includes the stored author name, content, mentions, and timestamps. Access requires an active authenticated operator session or an organization API key with the `conversations:read` scope. API-key calls also require the automation API module. Data is isolated to the authenticated organization; identifiers from another organization or site are not disclosed.