Skip to main content

Authentication

Every request to /v1 needs an API key of your company, sent as a Bearer token:

Authorization: Bearer mds_live_...

You create and revoke keys in the planner under Einstellungen → API-Schlüssel. A key is shown only once, when it is created. A key can expire on a date you set; otherwise it is valid until you revoke it. Without a key, or with a wrong, expired or revoked one, the API answers 401.

Scopes​

Each key has scopes that decide what it may do. read:… lets it read, write:… lets it create, change and delete, and includes reading: every write answers with the record it changed, so write:customers alone is enough to create customers and read them back. A request without the scope it needs answers 403 insufficient_scope, and required in the answer names the scope.

DataReadWrite
Projectsread:projectswrite:projects
Offers and offer requestsread:offerswrite:offers
Customersread:customerswrite:customers
Materialsread:materialswrite:materials
Manufacturersread:manufacturerswrite:manufacturers
Servicesread:serviceswrite:services
Company profile, team members and sitesread:companywrite:company
Bookings and appointment typesread:bookingswrite:bookings
Analyticsread:analytics—
Documents and grid operatorsread:documents—

You can only give a key scopes for things your own role in the planner allows you to do.

A few fields come from another area and need its scope as well. Without it they are null, and everything else works:

  • Bookings: the customer's phone, address, billing details and notes need read:customers; plannerName needs read:company.
  • Document options: product names need read:materials.

Whatever its scopes, a key only ever sees and changes the data of its own company.

Rate limits​

There are no rate limits today. Every request is logged per key (you see them under Einstellungen → API-Schlüssel), and limits may come later. So build your client to wait and retry on a 429 answer, keep the number of requests reasonable, and use webhooks instead of asking for changes again and again.

Errors​

StatuserrorMeaning
400validation_error, invalid_sortThe body, a parameter or the sort field is not valid; message says what.
401missing_api_key, invalid_api_keyNo key, or a wrong, expired or revoked one.
403insufficient_scopeThe key lacks the scope named in required.
404not_foundNo such record in your company.
409depends on the endpointNot possible in the record's current state; the endpoint lists its codes.
500, 502db_error, booking_failed, …Something failed on our side; message has the details.