SpotbookrBusiness

Spotbookr Business

Developers

Spotbookr Business API

Read and change a company's Spotbookr records from your own code, or from any tool that can call an API.

OpenAPI file

Start in four steps

  1. Get a key. The owner of the Spotbookr account signs in and opens Account, Integrations, names the key, chooses what it may do, and copies it. It is shown once.
  2. Check it works. Call GET https://work.spotbookr.com/api/v1/ping with the header Authorization: Bearer YOUR_KEY. The answer names the company and says what the key may do.
  3. Read something. GET /api/v1/contacts lists contacts. Every list has the same shape: data, total, limit, offset.
  4. Change something. POST adds a record and answers 201 with it; PATCH changes only the fields you send; DELETE removes it where that is allowed.

The rules

  • A key on every call, in the header Authorization: Bearer YOUR_KEY. Never put a key in a web address or in code that runs in a browser.
  • A key has a level: add leads only, read only, or read and change. It can also be limited to parts of the account.
  • JSON in, JSON out. Send Content-Type: application/json with POST and PATCH. Dates are YYYY-MM-DD; amounts are in the account's currency.
  • Pages. ?limit=50&offset=50 asks for the next page. The most in one page is 200.
  • Limit. 120 calls a minute from one address.
  • Automations and webhooks still run on what the API adds or changes.
  • A company's own fields travel inside custom, by name: {"custom": {"Region": "North"}}.

When a call is refused

The answer is {"error": {"code": "...", "message": "..."}}. The message says what to change.

400bad_requestThe body was not a JSON object.
401unauthorizedThe key is missing, wrong or revoked.
403forbiddenThe key is not allowed to do this: it is leads only, read only, or limited to other parts of the account.
404not_foundThere is no record with that id in your account.
409duplicate, in_use, not_allowed, product_offThe change conflicts with what is there: an email already used, a contact that still has deals, a board rule, or a product your company does not have.
422invalidA field is missing or has a value that is not accepted. The message names it.
429rate_limitedMore than 120 calls in a minute from one address.

Examples

Command line

curl https://work.spotbookr.com/api/v1/ping -H "Authorization: Bearer YOUR_KEY"

curl -X POST https://work.spotbookr.com/api/v1/contacts \
  -H "Authorization: Bearer YOUR_KEY" -H "Content-Type: application/json" \
  -d '{"name": "Dana Reyes", "email": "dana@example.com", "company": "Example Co", "tags": ["newsletter"]}'

curl -X PATCH https://work.spotbookr.com/api/v1/tasks/123 \
  -H "Authorization: Bearer YOUR_KEY" -H "Content-Type: application/json" -d '{"done": true}'

Python

import requests

api = "https://work.spotbookr.com/api/v1"
headers = {"Authorization": "Bearer YOUR_KEY"}

# every contact, a page at a time
offset = 0
while True:
    page = requests.get(api + "/contacts", headers=headers, params={"limit": 200, "offset": offset}).json()
    for contact in page["data"]:
        print(contact["name"], contact["email"])
    offset += page["limit"]
    if offset >= page["total"]:
        break

# open a deal for a contact
r = requests.post(api + "/deals", headers=headers, json={"name": "Website rebuild", "contact_id": 42, "value": 4800})
if r.status_code != 201:
    print(r.json()["error"]["message"])

JavaScript (on a server, not in a browser)

const api = "https://work.spotbookr.com/api/v1";
const headers = { Authorization: "Bearer " + process.env.SPOTBOOKR_KEY, "Content-Type": "application/json" };

const res = await fetch(api + "/tasks", {
  method: "POST", headers,
  body: JSON.stringify({ title: "Call back about pricing", due: "2026-11-03", contact_id: 42 }),
});
const body = await res.json();
if (!res.ok) throw new Error(body.error.message);
console.log(body.data.id);

Every call

General

GET/api/v1/pingCheck a key works. Answers with your company name.
GET/api/v1/usersThe people on your account, for use as owner_id or assignee_id.

Contacts

GET/api/v1/contactsList contacts. Filters: q, email, status, company_id.
POST/api/v1/contactsAdd a contact. Needs name. Also: email, phone, title, company, status, source, tags, address, notes, owner_id, custom.
GET/api/v1/contacts/{id}One contact.
PATCH/api/v1/contacts/{id}Change any of the same fields. Send only what changes.
DELETE/api/v1/contacts/{id}Delete a contact that has no deals.

Companies

GET/api/v1/companiesList companies. Filter: q.
POST/api/v1/companiesAdd a company. Needs name. Also: website, phone, industry, address, notes, tags, owner_id, custom.
GET/api/v1/companies/{id}One company.
PATCH/api/v1/companies/{id}Change a company. Renaming it renames it on its people.

Deals

GET/api/v1/dealsList deals. Filters: stage (a stage name, or open), pipeline (a pipeline name), contact_id, owner_id.
POST/api/v1/dealsOpen a deal. Needs name and contact_id. Also: value, pipeline, stage, expected_close, description, owner_id, tags, custom.
GET/api/v1/deals/{id}One deal.
PATCH/api/v1/deals/{id}Change a deal, or move it between your open stages. Winning, losing and reopening are done in Spotbookr.

Tasks

GET/api/v1/tasksList CRM tasks. Filters: done (true or false), owner_id, contact_id, deal_id.
POST/api/v1/tasksAdd a task. Needs title. Also: due, owner_id, contact_id, deal_id, notes.
GET/api/v1/tasks/{id}One task.
PATCH/api/v1/tasks/{id}Change a task, or finish it with "done": true.
DELETE/api/v1/tasks/{id}Delete a task.

Project Management

GET/api/v1/projectsList projects, each with the names of its columns.
GET/api/v1/projects/{id}/itemsA project's work items. Filters: done, assignee_id, type.
POST/api/v1/projects/{id}/itemsAdd a work item. Needs title. Also: type, description, assignee_id, priority, start_date, due_date, labels.
GET/api/v1/items/{id}One work item.
PATCH/api/v1/items/{id}Change a work item, or move it with "status": the name of a column. The board's own rules apply.

Invoicing (read only)

GET/api/v1/invoicesList invoices with their totals, balance and state. Filter: state.
GET/api/v1/estimatesList estimates.

Scheduling (read only)

GET/api/v1/appointmentsAppointments, meetings and work sessions between two dates. Filters: from, to (YYYY-MM-DD; the next 30 days when left out).
GET/api/v1/servicesThe services customers can book.

Leads

POST/api/v1/leadsAdd a lead in one call: a contact, a deal in your first stage and a task to reply. Needs name and email. Also: company, phone, message, source.

The fields of each record

Contact

name text, required
email text, unique among your contacts
phone text
title text
company text; the company record is found or made from it
status Lead, Prospect, Customer or Inactive
source text
tags list of text
address text
notes text
owner_id a person's id
custom your own fields, by name
id, company_id, created_at read only

Company

name text, required, unique
website text
phone text
industry text
address text
notes text
tags list of text
owner_id a person's id
custom your own fields, by name

Deal

name text, required
contact_id a contact's id, required when opening
value number, in your account's currency
pipeline the name of one of your pipelines, set when opening; your first pipeline when left out
stage one of the open stage names of the deal's pipeline
expected_close date
description text
owner_id a person's id
tags list of text
custom your own fields, by name
open read only: false once won or lost

Task

title text, required
due date
done true or false
owner_id a person's id
contact_id a contact's id
deal_id a deal's id
notes text

Work item

title text, required
type one of the project's types, such as Task, Story or Bug
description text
status the name of one of the project's columns
priority Lowest, Low, Medium, High or Highest
assignee_id a person's id
start_date, due_date date
labels list of text
key, done, status_category read only

Being told, instead of asking

To hear the moment something happens, such as a deal being won or an invoice being paid, use webhooks: Spotbookr sends a signed message to an address of yours. They are set up under Account, Integrations, and work alongside the API.

Questions about the API: support@spotbookr.com. More help is in the Help Center.