Connect external tools, scripts, and AI agents to your Apex Rental Pro workspace with scoped API keys.
This guide is the public developer reference for the stable /api/v1 surface. Browser routes under plain /api/... are for the signed-in app and are not the integration contract.
Quickstart
- Sign in as a tenant admin.
- Open Settings → API Keys.
- Name the key, choose only the scopes you need, optionally set an expiration or IP allowlist, then create it.
- Copy the secret immediately. Apex stores only a hash — the cleartext cannot be shown again.
- Copy the agent card (or a curl example below) and make your first call:
curl -sS -H "Authorization: Bearer arp_an_YOUR_SECRET" \
"https://YOUR-TENANT.apexrentalpro.com/api/v1/meta"
A successful response looks like:
{
"api": "apex-rental-pro",
"version": "v1",
"keyId": "...",
"keyName": "Website bridge",
"scopes": ["quotes:read", "inventory:read"]
}
Base URL
Every tenant has its own origin:
https://{tenant}.apexrentalpro.com
All public integration routes live under:
https://{tenant}.apexrentalpro.com/api/v1
Replace {tenant} with your workspace subdomain. The Settings agent card fills this in automatically from your workspace URL.
Authentication
Send the key on every request:
Authorization: Bearer arp_an_...
| Rule | Detail |
|---|---|
| Header only | Do not put the secret in the query string or JSON body |
| Prefix | Live secrets start with arp_an_ |
| Storage | Apex stores SHA-256 hashes only |
| Actor | API calls are audited as the key (API key: …), not as a human user session |
| Cookies | Session cookies are for the web UI. Integrations must use bearer keys |
Scopes
Keys never inherit a full admin session. You grant explicit scopes:
| Scope | What it allows |
|---|---|
quotes:read |
List and fetch quotes |
quotes:write |
Create and update quotes |
inventory:read |
List and fetch inventory items |
inventory:write |
Create and update inventory items |
bookings:read |
List and fetch booked events |
bookings:write |
Book a quote onto the calendar |
customers:read |
List and fetch customers |
email:send |
Send customer message emails (also needs Email Workflows on the plan) |
Missing scope responses look like:
{
"error": "Missing required scope: quotes:write",
"code": "api_key_scope_missing",
"requiredScope": "quotes:write"
}
Endpoint reference
Object-first map of the current public API. Use only these paths.
Meta
GET /api/v1/meta
Confirms the key works and returns its scopes.
Scope: any valid key
curl -sS -H "Authorization: Bearer $ARP_API_KEY" \
"$BASE/api/v1/meta"
Quotes
GET /api/v1/quotes
Scope: quotes:read
curl -sS -H "Authorization: Bearer $ARP_API_KEY" \
"$BASE/api/v1/quotes"
GET /api/v1/quotes/:id
Scope: quotes:read
POST /api/v1/quotes
Scope: quotes:write
curl -sS -X POST -H "Authorization: Bearer $ARP_API_KEY" \
-H "Content-Type: application/json" \
-d '{
"customer_name": "Ada Lovelace",
"customer_email": "[email protected]",
"event_date": "2026-09-20",
"items_json": "[{\"category\":\"Tents\",\"name\":\"20x20\",\"qty\":1,\"unit_price\":500}]"
}' \
"$BASE/api/v1/quotes"
Body fields
| Field | Required | Notes |
|---|---|---|
items_json |
Yes | JSON string or array of line items |
customer_name or customer_business_name |
Yes | At least one |
customer_email, customer_phone |
No | Contact fields |
event_date |
No | YYYY-MM-DD |
event_address, event_city, event_state, event_zip |
No | Location |
notes, private_notes |
No | Customer-facing vs internal |
delivery_fee, tax_rate, discount_amount, deposit_rate |
No | Pricing inputs |
tax_exempt, status |
No | Flags / status |
Line items commonly include category, name or description, qty / quantity, and unit_price.
PUT /api/v1/quotes/:id
Scope: quotes:write
Same body shape as create. Optional base_updated_at enables optimistic concurrency; a stale value returns 409.
POST /api/v1/quotes/:id/book
Scope: bookings:write
Books the quote onto the calendar. Safe to retry: if the quote is already booked, Apex returns the existing event instead of creating a duplicate.
curl -sS -X POST -H "Authorization: Bearer $ARP_API_KEY" \
-H "Content-Type: application/json" \
-d '{}' \
"$BASE/api/v1/quotes/123/book"
Inventory
GET /api/v1/inventory
Scope: inventory:read
Optional query: include_components=true.
Purchase and loan financial fields are not exposed on the public API.
GET /api/v1/inventory/:id
Scope: inventory:read
POST /api/v1/inventory
Scope: inventory:write
curl -sS -X POST -H "Authorization: Bearer $ARP_API_KEY" \
-H "Content-Type: application/json" \
-d '{
"category": "Chairs",
"name": "White Folding",
"total": 200,
"unit_price": 1.5
}' \
"$BASE/api/v1/inventory"
| Field | Required | Notes |
|---|---|---|
category |
Yes | Grouping label |
name |
Yes | Item name |
total |
Yes | On-hand quantity (not negative) |
unit_price |
No | Default unit price |
track_availability |
No | Defaults on |
customer_rentable |
No | Defaults on |
pricing_mode |
No | e.g. flat |
PUT /api/v1/inventory/:id
Scope: inventory:write
Bookings
Bookings are calendar events created from quotes or entered directly in Apex.
GET /api/v1/bookings
Scope: bookings:read
Optional query window:
?start=2026-09-01&end=2026-09-30
Customer contact fields on bookings are included only when the same key also has customers:read.
GET /api/v1/bookings/:id
Scope: bookings:read
Customers
GET /api/v1/customers
Scope: customers:read
GET /api/v1/customers/:id
Scope: customers:read
POST /api/v1/email/messages
Scope: email:send
Also requires the workspace Email Workflows entitlement. Without it, the API returns 402.
curl -sS -X POST -H "Authorization: Bearer $ARP_API_KEY" \
-H "Content-Type: application/json" \
-d '{
"customer_id": 42,
"body": "Hi — confirming we have you on the calendar for Saturday."
}' \
"$BASE/api/v1/email/messages"
Provide either:
customer_id, orcustomer_profilewith at leastname(and ideallyemail)
Errors
| Status | Code | Meaning |
|---|---|---|
401 |
api_key_required |
Missing, revoked, expired, or invalid bearer key |
403 |
api_key_scope_missing |
Key is valid but lacks the needed scope |
402 |
plan / entitlement codes | Feature not enabled on the billing plan (common for email) |
404 |
not_found |
Resource does not exist |
409 |
conflict / booking codes |
Stale update, booking already in progress, or similar conflict |
400 |
— | Validation problem; read error |
Error bodies are JSON:
{
"error": "API key authentication required",
"code": "api_key_required"
}
AI agent cards
Settings → API Keys generates a ready-to-paste agent card for each key.
The full card includes:
- your tenant base URL
- the bearer secret (only at creation time)
- granted scopes
- the exact endpoints that scope set unlocks
- hard rules (use
/api/v1, never browser cookie routes) - curl examples and common body shapes
- a link back to this guide
At creation: the card embeds the live secret. Copy it once into a private agent chat or password manager.
Later from the key list: the card uses arp_an_PASTE_SECRET_HERE. Paste your saved secret over that placeholder, or create a new key if the secret was lost.
Security checklist
- Grant the minimum scopes needed for the integration
- Prefer an expiration date for temporary agent experiments
- Use an IP allowlist when the caller has a stable egress address
- Revoke keys you no longer use
- Never commit secrets to git, public tickets, or shared Slack/Discord channels
- Do not send payment card numbers through this API — Apex does not accept raw card data here
Creating keys in the app
- Settings → API Keys
- Fill name + scopes
- Create
- Copy secret
- Copy agent card
- Optional: edit scopes/description/expiry later; revoke when finished
Related admin settings overview: Settings.
What this API is not
- Not a replacement for the full browser UI
- Not the mobile app token system (
arpm_at_…device tokens are separate) - Not the gateway super-admin API
- Not a public anonymous endpoint — every call needs a tenant key
Need help?
- Workspace sign-in help: start.apexrentalpro.com
- Support: Contact Apex
- Product guides index: Guides