+91-40-4033-4444 hello@office24by7.com Hyderabad, Telangana, India

Build on the Office24by7 API

One clean REST API across your whole platform — leads, contacts, deals, WhatsApp and SMS messaging, calls, tickets, invoices and your own custom objects. Predictable JSON, signed webhooks, official SDKs and a full sandbox. Ship your first call in minutes.

Built for builders

Everything you need to integrate

One consistent, versioned REST API spanning CRM, communication, Custom Applications and data — with the primitives real integrations depend on.

REST API

Versioned, JSON-over-HTTPS endpoints for leads, contacts, deals, messages, calls, tickets and invoices — cursor-paginated and idempotent by design.

Webhooks

Subscribe to signed events and react in real time, with HMAC-SHA256 verification and automatic retries using exponential backoff.

Official SDKs

First-party libraries for Node.js, Python, PHP and Java, so you spend your time on logic instead of plumbing.

Sandbox & test keys

Build and test against an isolated sandbox with o24_test_ keys, then switch to production o24_live_ keys when you’re ready.

Custom objects & fields

Read and write your own objects and fields through the same API surface as native modules. Explore Custom Objects →

Integrations & data

Prefer no-code? Connect your stack via integrations, or pull governed records from the data & analytics layer.

Quickstart

Your first API call

The Office24by7 REST API lets you programmatically manage leads, contacts, deals, omnichannel messaging (WhatsApp and SMS), telephony, support tickets and invoices across your CRM, communication and Custom Applications workspaces. All endpoints are versioned, JSON-based and served over HTTPS.

curl -X POST https://api.office24by7.com/v1/leads \ -H "Authorization: Bearer o24_live_xxx" \ -H "Content-Type: application/json" \ -H "Idempotency-Key: 8f2a1c9e-lead-01" \ -d '{ "name": "Anita Sharma", "email": "anita@example.in", "phone": "+919812345678", "source": "website" }'
const res = await fetch("https://api.office24by7.com/v1/leads", { method: "POST", headers: { "Authorization": "Bearer o24_live_xxx", "Content-Type": "application/json", "Idempotency-Key": "8f2a1c9e-lead-01" }, body: JSON.stringify({ name: "Anita Sharma", email: "anita@example.in", phone: "+919812345678", source: "website" }) }); const lead = await res.json(); console.log(lead.id);
import requests resp = requests.post( "https://api.office24by7.com/v1/leads", headers={ "Authorization": "Bearer o24_live_xxx", "Idempotency-Key": "8f2a1c9e-lead-01", }, json={ "name": "Anita Sharma", "email": "anita@example.in", "phone": "+919812345678", "source": "website", }, ) print(resp.json()["id"])
Authentication

Secure by default

Authenticate every request with a Bearer token. Generate API keys from Admin Console > Settings > API Keys; each key is prefixed o24_live_ for production or o24_test_ for sandbox, and is passed in the Authorization header as 'Authorization: Bearer o24_live_...'.

Treat API keys as secrets: store them server-side, never expose them in browser or mobile code, rotate them periodically, and issue separate least-privilege keys scoped to only the resources each integration needs.

Base URL

https://api.office24by7.com/v1

Conventions

  • ✓ All requests and responses use JSON (application/json) over HTTPS; plaintext HTTP is rejected.
  • ✓ Timestamps are UTC in ISO-8601 format (e.g. 2026-07-22T09:30:00Z).
  • ✓ List endpoints are cursor-paginated via limit and cursor query params, returning a next_cursor in the response.
  • ✓ Rate limits apply per key; exceeding them returns HTTP 429 with a Retry-After header telling you when to retry.
  • ✓ Send an Idempotency-Key header on POST requests to safely retry without creating duplicates.
  • ✓ Errors return a consistent shape: {"error":{"code":"...","message":"...","request_id":"..."}} with an appropriate 4xx/5xx status.
API reference

Resources & endpoints

Leads

Capture and manage sales leads flowing into the CRM from web forms, ads and campaigns.

POST/leadsCreate a lead
GET/leads/{id}Retrieve a lead
GET/leadsList/search leads
PATCH/leads/{id}Update a lead
POST/leads/{id}/convertConvert a lead to a contact and deal

Contacts

People and accounts in your CRM, including phone, email and WhatsApp identities.

POST/contactsCreate a contact
GET/contacts/{id}Retrieve a contact
GET/contactsList/search contacts
PATCH/contacts/{id}Update a contact
DELETE/contacts/{id}Delete a contact

Deals

Sales opportunities moving through your pipeline stages toward close.

POST/dealsCreate a deal
GET/deals/{id}Retrieve a deal
GET/dealsList/search deals
PATCH/deals/{id}Update a deal or move its stage

Messages

Send and track outbound messages over the WhatsApp Business API and DLT-registered SMS.

POST/messages/whatsappSend a WhatsApp template message
POST/messages/smsSend a DLT-approved SMS
GET/messages/{id}Retrieve a message and its status
GET/messagesList/search messages

Calls

Initiate and manage cloud telephony calls, including click-to-call and IVR flows.

POST/callsInitiate a click-to-call
GET/calls/{id}Retrieve a call and its recording
GET/callsList/search calls
POST/calls/{id}/hangupEnd an in-progress call

Tickets

Support tickets raised by customers across email, chat and telephony channels.

POST/ticketsCreate a ticket
GET/tickets/{id}Retrieve a ticket
GET/ticketsList/search tickets
PATCH/tickets/{id}Update a ticket status or assignee
POST/tickets/{id}/commentsAdd a comment to a ticket

Invoices

Billing documents issued to customers from Custom Applications (Invoicing), including GST details.

POST/invoicesCreate an invoice
GET/invoices/{id}Retrieve an invoice
GET/invoicesList/search invoices
POST/invoices/{id}/sendEmail an invoice to the customer
More examples

Common flows

Send a WhatsApp template · cURL

curl -X POST https://api.office24by7.com/v1/messages/whatsapp \ -H "Authorization: Bearer o24_live_xxx" \ -H "Content-Type: application/json" \ -d '{ "to": "+919812345678", "template": "order_confirmation", "language": "en", "components": [ { "type": "body", "parameters": [ { "type": "text", "text": "INV-2048" } ] } ] }'

Verify a webhook · Node.js

const crypto = require("crypto"); function verify(rawBody, signature, secret) { const expected = crypto .createHmac("sha256", secret) .update(rawBody, "utf8") .digest("hex"); return crypto.timingSafeEqual( Buffer.from(expected), Buffer.from(signature) ); } // app.post('/webhooks', (req, res) => { // const ok = verify(req.rawBody, req.get("X-O24-Signature"), process.env.O24_WEBHOOK_SECRET); // res.sendStatus(ok ? 200 : 400); // });
Webhooks & SDKs

React to events in real time

Office24by7 delivers events to your registered HTTPS endpoint as JSON POST requests, retrying with exponential backoff on non-2xx responses. Verify authenticity by computing an HMAC-SHA256 of the raw request body with your webhook signing secret and comparing it to the X-O24-Signature header.

lead.createdlead.updateddeal.stage_changeddeal.wonmessage.deliveredmessage.failedcall.completedcall.missedticket.createdticket.resolvedinvoice.paid

Official SDKs

Node.jsPythonPHPJavaGo (community)

Ready to build?

Create a free workspace, generate sandbox keys in the admin console and ship your first integration today — no sales call required.