V3 communications
For new V3 features, send email and SMS inside a server-side App Action. Browser code may invoke that Action, but must not call the app-token send REST or JS APIs directly. The Action decides whether the caller may perform the operation and derives permitted recipients from trusted server data. For in-app and push notifications, see V3 notifications.
See Send communications from a server Action for a complete example with a manual trigger, verified caller, and recipient lookup. Add fliplet-communicate to the Action’s dependencies when it uses Fliplet.Communicate.
Direct browser email and SMS sends still work in existing V3 apps during migration; they lack feature-specific authorization and a V3-wide block is planned for a later release. Fliplet.Communicate.sendPushNotification() already requires app publisher or editor access. This guidance does not affect composing an email on the device or sharing a URL. The shared Communicate API reference retains those methods and the V2 send examples.