Lists visitors for the current organization with pagination and optional filters for search, status, tags, blocked state, visit counts, and last-seen range. When both page and offset are sent, page takes precedence. Authenticate with an organization API key sent in `X-API-Key` or as a Bearer token and carrying the exact `visitors:read` scope. API-key access also requires the Automation & API module (`automation_api`). Authorized dashboard sessions remain supported where the route already permits them. The request is isolated to the authenticated organization. Resource and site/project identifiers must belong to that organization; out-of-scope identifiers are not disclosed. Use the returned pagination metadata rather than inferring another page from the item count. Filters and search are evaluated only against visitors in the authenticated organization. Retry behavior: This read-only operation is safe to retry.
/api/visitorsOrganization API key supplied as Authorization: Bearer convor_sk_....
In: header
application/json
application/json
application/json
application/json
application/json
application/json
application/json
application/json
application/json
{
"data": [
{
"id": "550e8400-e29b-41d4-a716-446655440000",
"orgId": "770e8400-e29b-41d4-a716-446655440000",
"identifier": "[email protected]",
"fingerprint": "fp_123",
"firstSeenAt": "2026-06-20T08:00:00.000Z",
"lastSeenAt": "2026-06-23T08:00:00.000Z",
"totalSessions": 5,
"geoCountry": "US",
"geoCity": "New York",
"metadata": {},
"browser": {
"name": "Chrome",
"version": "126.0",
"os": "macOS"
},
"lastPage": "https://customer.example.org/pricing"
}
],
"pagination": {
"totalItems": 1,
"page": 1,
"pageSize": 20,
"hasNextPage": false,
"hasPrevPage": false
}
}{
"error": {
"code": "string",
"message": "string",
"fields": {
"property1": "string",
"property2": "string"
},
"details": {},
"correlationId": "string"
}
}{
"error": {
"code": "string",
"message": "string",
"fields": {
"property1": "string",
"property2": "string"
},
"details": {},
"correlationId": "string"
}
}{
"error": {
"code": "string",
"message": "string",
"fields": {
"property1": "string",
"property2": "string"
},
"details": {},
"correlationId": "string"
}
}{
"error": {
"code": "string",
"message": "string",
"fields": {
"property1": "string",
"property2": "string"
},
"details": {},
"correlationId": "string"
}
}{
"error": {
"code": "string",
"message": "string",
"fields": {
"property1": "string",
"property2": "string"
},
"details": {},
"correlationId": "string"
}
}{
"error": {
"code": "string",
"message": "string",
"fields": {
"property1": "string",
"property2": "string"
},
"details": {},
"correlationId": "string"
}
}{
"error": {
"code": "string",
"message": "string",
"fields": {
"property1": "string",
"property2": "string"
},
"details": {},
"correlationId": "string"
}
}{
"error": {
"code": "string",
"message": "string",
"fields": {
"property1": "string",
"property2": "string"
},
"details": {},
"correlationId": "string"
}
}curl --request GET \
'https://api.convor.io/api/visitors' \
--header 'Accept: application/json' \
--header 'Authorization: Bearer convor_sk_...'const response = await fetch("https://api.convor.io/api/visitors", {
method: "GET",
headers: {
"Accept": "application/json",
"Authorization": "Bearer convor_sk_..."
},
});
const contentType = response.headers.get("content-type") ?? "";
const data = response.status === 204
? null
: contentType.includes("json")
? await response.json()
: contentType.startsWith("text/")
? await response.text()
: await response.blob();
if (!response.ok) {
const message = typeof data === "object" && data !== null
&& "error" in data && typeof data.error === "object"
&& data.error !== null && "message" in data.error
? String(data.error.message)
: "Convor API request failed (" + response.status + ")";
throw new Error(message);
}
console.log(data);Was this page helpful?
Get visitor statistics
Returns visitor totals, online visitor count, new-versus-returning counts, and top countries for the requested period. `period` defaults to `24h` and accepts `24h`, `7d`, or `30d`. `onlineNow` counts visitors seen in the last five minutes. Authenticate with an organization API key sent in `X-API-Key` or as a Bearer token and carrying the exact `visitors:read` scope. API-key access also requires the Automation & API module (`automation_api`). Authorized dashboard sessions remain supported where the route already permits them. The request is isolated to the authenticated organization. Resource and site/project identifiers must belong to that organization; out-of-scope identifiers are not disclosed. Statistics are calculated for the authenticated organization and can lag recent write-side events while asynchronous analytics are being processed. Retry behavior: This read-only operation is safe to retry.
Merge duplicate visitor profiles
Atomically reassigns conversations, visitor messages, surveys, CSAT responses, and pending outbox records from one or more source visitors to the target. Profile metadata and session statistics are merged before the source records are deleted. Authenticate with an organization API key sent in `X-API-Key` or as a Bearer token and carrying the exact `visitors:write` scope. API-key access also requires the Automation & API module (`automation_api`). Authorized dashboard sessions remain supported where the route already permits them. The request is isolated to the authenticated organization. Resource and site/project identifiers must belong to that organization; out-of-scope identifiers are not disclosed. Merging moves compatible data from the source visitor into the target visitor and removes or redirects the source according to the response. Both IDs must belong to the authenticated organization. Never retry blindly after an ambiguous timeout; read both visitors first. Retry behavior: This operation is not idempotent. After an ambiguous timeout, read the resource state before retrying to avoid duplicate work, messages, files, bookings, exports, or events.