The public API
Every site-kit module talks to Sonor over one public API at https://api.sonor.io/api/public. site-kit is the supported way to use it: it handles auth, caching, the site host, retries and spam defense for you. This page is for when you need to know what's underneath.
Authentication
Every request carries the project's key in the x-api-key header:
curl https://api.sonor.io/api/public/... \
-H 'x-api-key: sonor_xxxxxxxx_xxxxx'The key identifies the project, so a request never sends a project id. Keys look like sonor_{first 8 characters of the project id}_{secret}. A site sets one variable, SONOR_API_KEY, and SiteKitLayout passes the browser a short-lived credential for the calls that happen there.
Multi-site projects
One Sonor project can serve many domains: a company site plus regional microsites, say. Reads and writes carry the site host (?site= on reads, a site field on writes) so each domain gets its own pages, forms and analytics. site-kit sends it automatically from NEXT_PUBLIC_SITE_URL.
What's there
The API is grouped the way the site-kit modules are:
| Area | site-kit module |
|---|---|
| SEO metadata, schema, FAQs, sitemaps, redirects | SEO, Sitemap, Redirects |
| Analytics events, page views and Web Vitals | Analytics |
| Forms and submissions | Forms |
| Articles | Articles |
| Reviews and testimonials | Reputation |
| Products, services, events and checkout | Commerce |
| Booking availability | Booking |
| Chat, popups and banners | Website chat |
| llms.txt and answer-engine data | llms.txt and AEO |
| Agent tool-call reports | MCP and agent tools |
| Listings and search | re-site-kit |
| Portfolio and case studies | agency-site-kit |
Forms go through site-kit
A form submission is only accepted with evidence that a real browser rendered the page it came from. <ManagedForm> and the headless useForm hook send that evidence automatically; a hand-rolled fetch, or a proxy through your own API route, can't. Sonor refuses those before anything is written, so the visitor sees an error and you get no lead.
So:
- Use
<ManagedForm>, oruseFormwhen the design needs its own markup. - Define the form's fields in Sonor, so both can render and validate them.
- Send routing to different inboxes from Sonor (one form per destination), not from a proxy.
- For agents, turn on "Agent inquiries" for the form and use the MCP
send_inquirytool. See Agents and AI visibility.
Using the API from something other than Next.js
site-kit targets Next.js 16. From another stack, the data reads (SEO, articles, reviews, llms data) work over plain HTTP with the key. Forms don't, for the reason above. If you're planning a non-Next integration, talk to us first at sonor.io.