Build your own website
The Wzgate public API — what it serves, what you can build on it, and the four values you need from the CRM before you write a line of code.
Everything a visitor sees on a Wzgate-powered website comes from one API:
/api/public/*. It is anonymous — no staff login, no CRM account — and it is
scoped to one site, so a request only ever returns the content of the
website it came from.
The same API is what the CRM's own reference site runs on. There is nothing privileged in it that your site cannot use.
What you can build
An organization in the CRM can run several public websites. Each one is a site with its own key, its own domains and its own settings, and its type decides what the API serves it:
| Site type | What the API gives you |
|---|---|
| Real estate | The catalogue — properties, projects, developers, locations, amenities, the map and the search index — plus leads, viewing requests, visitor accounts, saved searches and the owner portal. |
| Stays | The short-stay portal and its search (/public/portal, /public/stays/search, booking calendars). |
| Company profile | The organization's own content: profile, about text, legal pages, blog, newsletter and the contact form. |
Every site type also serves the company profile, the blog and the lead form — those are how any website tells a visitor who you are and captures an enquiry.
What you send on every request
Two facts travel with each call:
- Which site this is — a site key in
X-Site, or a domain you have added to the site. See Identify your site. - Which integration is calling — an API key in
X-Api-Key. See Keys and CORS.
Writes that a bot would abuse also carry a Cloudflare Turnstile token; see Bot protection.
The four things you need from the CRM
Open the CRM, go to Settings → Websites, pick your site, and open the Connect your website tab. Everything below is on that one screen.
- API base URL — the CRM host plus
/api, for examplehttps://crm.example.com/api. Every path in these docs is written under it:/public/propertiesis reallyGET https://crm.example.com/api/public/properties. - Site key — the short identifier of this site (
niche,zos10, …). You send it asX-Site. - Publishable key (
pk_…) — the key your browser code sends. It is not a secret; it only works from your own domains. A secret key (sk_…) is available in the same card for your server. - Allowed domains — the hosts this site answers. They decide CORS, they resolve the site without a header, and they are what makes a publishable key valid. Add them on the Domains tab.
Where to go next
- Quick start — a working Next.js call in ten minutes.
- Identify your site — domain,
X-Site, and the deprecatedX-Subdomain. - Keys and CORS — publishable versus secret, rotation, and why an origin is checked.
- Bot protection — Turnstile on the five abused writes.
- Errors — the error body and every code you can branch on.
- Visitor accounts — register, verify, sign in, and the visitor token.
- Rate limits — the ceilings and how to survive a 429.
- API reference — every endpoint, generated from the API itself.
- Changelog — what changed, and what is being removed.