API reference
All 259 public operations, grouped by product area.
The complete machine-readable schema of every operation is openapi.json.
Appointments engine
Services, staff and appointments. Session-authenticated, engine-guarded: a hospitality org gets 403.
Hospitality engine
Tables, service periods and reservations. Session-authenticated, engine-guarded: an appointments org gets 403.
Public booking (appointments)
Unauthenticated. The widget a customer uses at /book/{slug} (or /{slug}/book: both are real, permanently-live addresses for the same page). Not engine-guarded: see the 403 note above.
| Method | Operation |
|---|---|
GET | List bookable appointment slots |
POST | Book an appointment (guest checkout) |
POST | Preview a promo code before checkout (public, unauthenticated) |
Public booking (hospitality)
Unauthenticated, two-step (hold, then confirm). Refuses an appointments org with 404.
Guest self-service
Unauthenticated except for the booking's manage token, which is the whole credential. One endpoint serves both engines because a manage link points at a booking, not at a product.
Agent (MCP)
One unauthenticated JSON-RPC endpoint (Model Context Protocol) that lets an AI assistant read the public booking surface on a guest's behalf. Not REST, and deliberately documented here anyway: it is a public endpoint on this domain, and an agent that reads this document is exactly the reader it is for. Distinct from the PRIVATE per-tenant MCP server, which is not built, is gated behind an sk_live_ key, and never takes a venue as an argument.
| Method | Operation |
|---|---|
POST | Public booking MCP endpoint (JSON-RPC) |
Shared
Clients, teammates, messages, notes, templates, branding, profile, account, organization settings. Deliberately NOT engine-guarded: a client record and a teammate mean the same thing to both products, and guarding these would lock half the product out of its own settings.
API keys
Issue and revoke the credentials programmatic callers use. Session-authenticated and admin-only, and deliberately unreachable with an API key: there is no scope for key management, so a leaked key cannot mint another.
| Method | Operation |
|---|---|
POST | Issue an API key (admin) |
DELETE | Revoke an API key (admin) |