Connect your shop to the rest of your software
The Promec REST API lets your accountant, your ERP, a customer's fleet manager or your own website read and write shop data without spreadsheets going back and forth. The shop's management switches it on, with scopes per area and a log of every request.
- 38endpoints in v1
- 27webhook events
- 60requests per minute per key
curl https://your-shop.example/api/v1/ping \ -H "Authorization: Bearer pt_test_9f2c…"
{
"ok": true,
"key": { "name": "CRM", "environment": "test",
"scopes": ["clients:read", "budgets:read"] },
"rate_limit": {
"per_minute": { "limit": 60, "remaining": 59 },
"per_day": { "limit": 2000, "remaining": 1999 }
},
"version": "v1"
}- GDPR: a stated purpose on every key
- Each key bound to one shop
- HMAC-SHA256 signed webhooks
- 90-day request log
- Idempotency-Key on writes
- Invoices issued only in the app
What shops use it for
Integrations people actually ask us for. If yours isn't here, tell us about it — it usually fits the endpoints that already exist.
Accountant and bookkeeping
Your accountant pulls the month's issued invoices, PDFs and payments directly, instead of chasing you by email. Invoices are read-only through the API; issuing them stays in the program so numbering stays compliant.
Group or dealer ERP
If the shop belongs to a group, keep clients, vehicles and quotes in sync with the central system and get notified the moment an invoice is issued.
Fleets and leasing
The fleet manager checks where each vehicle is in the process and when its inspection is due, and gets a webhook when it arrives, when it's ready and when it's handed back.
Parts suppliers
A distributor can open quotes with the part numbers already on each line, or read a job's lines to prepare the order.
Your website or app
Your site reads the free slots in the real diary and proposes the appointment. You confirm it in one click — or, in direct-booking mode, it goes straight in.
Make, n8n or Zapier
Receive events by webhook and chain whatever you need: a task in your CRM when a quote is rejected, a row in a sheet every time a payment comes in.
How it works
From your first key to a live integration without setting up a single server. The API is already part of your Promec.
- Create a test keyIn Developers / API, the shop's management creates the key with a name, the purpose of the integration and scopes per area. The full key is shown only once.
- Call /pingUsing your shop's URL (https://<your-domain>/api/v1). It returns the key's scopes and how much of today's quota is left.
- Build against real datapt_test_ keys read the shop's real data but can't create, change or send anything, and they don't use quota. Mistakes cost nothing.
- Go live and subscribe to webhooksOnce everything checks out, create a pt_live_ key and register the URL that will receive events. Every change is signed as “API · key name”.
curl -X POST https://your-shop.example/api/v1/budgets \ -H "Authorization: Bearer pt_live_4b7e…" \ -H "Idempotency-Key: 7c1d0e52-9a3f-4f0b" \ -H "Content-Type: application/json" \ -d '{"client_id": 1204, "vehicle_id": 871, "lines": [{"description": "Oil and filter change", "quantity": 1, "unit_price": 65, "line_type": "labor"}]}'
{
"id": 5821,
"status": "Pendiente",
"channel": "API",
"client_id": 1204,
"totals": { "base": 65, "tax": 13.65, "total": 78.65 },
"tracking_url": "…/public/seguimiento?id=…"
}Available resources
What an integration can read and write in version 1. Each resource has its own scope, so every key only sees what it needs.
Clients
Search by name, phone or email, and create or edit client records with their contact details.
- GET
/clients - POST
/clients - GET
/clients/{id} - PATCH
/clients/{id}
Vehicles
Look up by plate or by client, create and edit, with mileage and inspection due date.
- GET
/vehicles - POST
/vehicles - GET
/vehicles/{id} - PATCH
/vehicles/{id}
Quotes
Create quotes with their lines, move them through statuses and attach photos or PDFs. Only the customer can accept, from their link.
- GET
/budgets - POST
/budgets - GET
/budgets/{id} - POST
/budgets/{id}/lines - +4 more
Invoices and PDF
Issued invoices with lines, totals per tax rate, payments and the original PDF. Read-only.
- GET
/invoices - GET
/invoices/{id} - GET
/invoices/{id}/pdf
Appointments
Free slots using the diary's own rules (opening hours, bays, holidays), plus proposals and confirmed bookings.
- GET
/appointments - POST
/appointments - GET
/appointments/availability - DELETE
/appointments/{id}
Catalog
The shop's services and rates, so your website or configurator shows the same prices.
- GET
/catalog/services - GET
/catalog/rates
Communications
Log of emails, texts, WhatsApp messages and calls. On Business, send email and SMS too.
- GET
/communications - GET
/logs - POST
/email - POST
/sms
Webhooks
Per-event subscriptions with HMAC-SHA256 signatures, retries and an on-demand test delivery.
Some events
Built for integrations that don't break
The details that usually cause trouble in an integration, handled out of the box.
Keys created by management
The shop owner or manager creates each key with a name, a stated purpose and its scopes. The full key is shown once; after that only its prefix is visible.
Scopes per area
Clients, vehicles, quotes, invoices, appointments, catalog and communications, with read and, where it makes sense, write access. Your accountant's key has no business seeing the diary.
Test and live
pt_test_ keys read real data but can't create or change anything, and they don't use quota. Once the integration works, you create a pt_live_ key.
Signed webhooks
Promec calls your URL when something happens: 27 events, from “quote accepted” to “vehicle ready”. Every delivery is signed with HMAC-SHA256 and retried up to 5 times if your server doesn't answer.
Visible limits
60 requests per minute per key (up to 600 on request) plus your plan's daily quota. Every response carries X-RateLimit-Remaining; go over and you get a 429 with Retry-After.
No duplicate writes
Every POST carries an Idempotency-Key: if your system retries after a network drop, you won't end up with a second client or a second quote.
Security and GDPR
An integration shouldn't open more doors than it needs. This is how it's built:
One key, one shop
Only a hash of the key is stored, bound to the shop's instance: it's useless anywhere else and nobody can recover it, us included.
Purpose is mandatory
When creating a key you have to state what the data will be used for, as GDPR requires. It stays next to the key and in the log.
Internal data stays internal
Costs, margins, internal notes and internal-use quotes never appear in a response. Shop staff only show up as an id and a name.
Every request logged
Which key, from which IP, to which endpoint and with what result. Kept for 90 days and visible in the same section.
IP allow lists and expiry
Restrict a key to the IPs of the provider using it and give it an end date. Revoking it takes effect immediately.
The customer signs, not the API
Quote approval always comes from the customer through their signed link; the API cannot approve on their behalf.
API plans
Separate from your Promec plan. Start on Included and only move up if you need to write data, receive webhooks or handle more volume.
- 1 live key
- Read-only, every area
- 2,000 requests a day
- Pauses at the quota until 00:00 UTC
- 5 live keys
- Read and write
- Webhooks
- 20,000 requests a day
- Unlimited keys
- Everything in Developer
- Email and SMS sending via the API (messages billed separately)
- 100,000 requests a day
- Email support
- For companies connecting their product to several shops
- Custom quota, keys and scopes
- Volume pricing
Prices exclude taxes. Test keys are free and never count towards quota, and neither do tests run from the panel. If Developer or Business go over their monthly allowance (daily quota × days in the month), the excess is billed at €1 per 1,000 requests.
Frequently asked questions
Do I have to pay to use the API?
No. The Included plan comes with any Promec plan: one read-only key and 2,000 requests a day. You only pay if you need to write data, use webhooks or need more volume.
Where do I find my shop's API URL?
In the Developers / API section of Promec. Every shop runs on its own domain, so the base URL looks like https://<your-domain>/api/v1.
Can I issue invoices through the API?
No. You can read invoices with their PDF and payments, but they're issued from the program so numbering and any tax-authority reporting stay correct.
What if the integration gets something wrong?
A test key can't change anything. With a live key, every change is recorded in the client's or quote's history as “API · key name”, and you can revoke the key instantly.
Is there an SDK or a Postman collection?
The OpenAPI 3.1 file lets you generate a client in any language. Inside Promec you'll also find a Postman collection and a panel to try every endpoint with your own key.
I build software for repair shops — can I connect to many of them?
Yes, on the Partner plan: each shop creates a key for your product and we agree a per-shop price based on volume. Get in touch and we'll work it out.
What happens if I hit the rate limit?
Each key allows 60 requests per minute. Go over and the API answers 429 with a Retry-After header, so your system just waits that many seconds. On Included, the daily quota pauses the key until 00:00 UTC; on Developer and Business requests keep going through and the excess is billed at €1 per 1,000.
Can the API accept a quote on the customer's behalf?
No. Acceptance is always signed by the customer from their tracking link. If an integration tries to set a quote to approved, it gets a 403 with the link to send the customer instead.
Got an integration in mind?
Tell us what you want to connect and we'll point you to the right endpoints and the plan that fits.