API reference
Every public endpoint, generated from the API's own OpenAPI document — request parameters, bodies, responses and example calls.
The pages in this section are generated from the CRM's own OpenAPI document, so they describe the API as it actually is, not as somebody remembered it. Each page is one operation: its parameters, its request body, its responses and a ready-to-run example.
Before you read an endpoint
Three things are true of every operation here and are therefore not repeated on each page:
- Paths are absolute.
/api/public/propertiesis the whole path; the API base URL from the Connect tab already ends in/api, so you call`${API}/public/properties`. - Headers. Every operation declares
X-SiteandX-Api-Key; the five bot-protected writes also declareX-Turnstile-Token. See Identify your site and Keys and CORS. - Envelope. Responses are wrapped in
{ success, data, message? }, withpaginationbesidedataon paginated lists. The schemas below describe the payload — what you find insidedata. See the quick start.
The server shown on each page is a placeholder. Your host is the API base URL in Settings → Websites → Connect your website.
The raw document
The same document is served by your CRM at GET <host>/public-openapi.json — no
authentication, no staff routes. Point a client generator at it, or diff it
between releases to see what moved.
This reference covers the public API only. Everything a signed-in visitor can do is in it; nothing a CRM user can do is.