DevelopersREST API
REST API
Organisation-scoped HTTP at /api/v1. Safe writes, no deletes, OpenAPI included.
Base URL: https://{your-org}.doorops.com/api/v1
See authentication for keys. The live OpenAPI playground is at /docs/api.
Scopes
Tick only what the integration needs. Writes still pass Laravel policies.
customers:read/customers:writesites:read/sites:writejobs:read/jobs:writeassets:readquotes:readinvoices:readforms:read/forms:writefleet:read/fleet:writereports:readtelephony:read/telephony:write
What you can call today
| Method | Path |
|---|---|
| GET | /ping |
| GET, POST | /customers |
| GET, PATCH | /customers/{customer} |
| GET, POST | /sites |
| GET, PATCH | /sites/{site} |
| GET, POST | /sites/{site}/contacts |
| GET | /jobs |
| GET | /jobs/{job} |
| PATCH | /jobs/{job}/status |
| GET | /assets, /assets/{asset} |
| GET | /quotes, /quotes/{quote} |
| GET | /invoices, /invoices/{invoice} |
| GET | /reporting/snapshot, /reporting/jobs |
| GET, POST | /telephony/calls |
| GET | /telephony/calls/{call} |
| GET | /fleet/vehicles |
| POST | /fleet/vehicle-locations |
Hosted OpenAPI UI (try-it, needs a session): doorops.com/docs/api
Conventions
- JSON in and out
- Tenant isolation is the host, not a header you can spoof
- Unknown cross-tenant ids return not found, not a leak
- Pagination is server-side on list endpoints