Build on the Office24by7 API
One clean REST API across your whole platform — leads, contacts, deals, WhatsApp and SMS messaging, calls, tickets, invoices and your own custom objects. Predictable JSON, signed webhooks, official SDKs and a full sandbox. Ship your first call in minutes.
Everything you need to integrate
One consistent, versioned REST API spanning CRM, communication, Custom Applications and data — with the primitives real integrations depend on.
REST API
Versioned, JSON-over-HTTPS endpoints for leads, contacts, deals, messages, calls, tickets and invoices — cursor-paginated and idempotent by design.
Webhooks
Subscribe to signed events and react in real time, with HMAC-SHA256 verification and automatic retries using exponential backoff.
Official SDKs
First-party libraries for Node.js, Python, PHP and Java, so you spend your time on logic instead of plumbing.
Sandbox & test keys
Build and test against an isolated sandbox with o24_test_ keys, then switch to production o24_live_ keys when you’re ready.
Custom objects & fields
Read and write your own objects and fields through the same API surface as native modules. Explore Custom Objects →
Integrations & data
Prefer no-code? Connect your stack via integrations, or pull governed records from the data & analytics layer.
Your first API call
The Office24by7 REST API lets you programmatically manage leads, contacts, deals, omnichannel messaging (WhatsApp and SMS), telephony, support tickets and invoices across your CRM, communication and Custom Applications workspaces. All endpoints are versioned, JSON-based and served over HTTPS.
curl -X POST https://api.office24by7.com/v1/leads \
-H "Authorization: Bearer o24_live_xxx" \
-H "Content-Type: application/json" \
-H "Idempotency-Key: 8f2a1c9e-lead-01" \
-d '{
"name": "Anita Sharma",
"email": "anita@example.in",
"phone": "+919812345678",
"source": "website"
}'const res = await fetch("https://api.office24by7.com/v1/leads", {
method: "POST",
headers: {
"Authorization": "Bearer o24_live_xxx",
"Content-Type": "application/json",
"Idempotency-Key": "8f2a1c9e-lead-01"
},
body: JSON.stringify({
name: "Anita Sharma",
email: "anita@example.in",
phone: "+919812345678",
source: "website"
})
});
const lead = await res.json();
console.log(lead.id);import requests
resp = requests.post(
"https://api.office24by7.com/v1/leads",
headers={
"Authorization": "Bearer o24_live_xxx",
"Idempotency-Key": "8f2a1c9e-lead-01",
},
json={
"name": "Anita Sharma",
"email": "anita@example.in",
"phone": "+919812345678",
"source": "website",
},
)
print(resp.json()["id"])Secure by default
Authenticate every request with a Bearer token. Generate API keys from Admin Console > Settings > API Keys; each key is prefixed o24_live_ for production or o24_test_ for sandbox, and is passed in the Authorization header as 'Authorization: Bearer o24_live_...'.
Treat API keys as secrets: store them server-side, never expose them in browser or mobile code, rotate them periodically, and issue separate least-privilege keys scoped to only the resources each integration needs.
Base URL
https://api.office24by7.com/v1Conventions
- ✓ All requests and responses use JSON (application/json) over HTTPS; plaintext HTTP is rejected.
- ✓ Timestamps are UTC in ISO-8601 format (e.g. 2026-07-22T09:30:00Z).
- ✓ List endpoints are cursor-paginated via limit and cursor query params, returning a next_cursor in the response.
- ✓ Rate limits apply per key; exceeding them returns HTTP 429 with a Retry-After header telling you when to retry.
- ✓ Send an Idempotency-Key header on POST requests to safely retry without creating duplicates.
- ✓ Errors return a consistent shape: {"error":{"code":"...","message":"...","request_id":"..."}} with an appropriate 4xx/5xx status.
Resources & endpoints
Leads
Capture and manage sales leads flowing into the CRM from web forms, ads and campaigns.
Contacts
People and accounts in your CRM, including phone, email and WhatsApp identities.
Deals
Sales opportunities moving through your pipeline stages toward close.
Messages
Send and track outbound messages over the WhatsApp Business API and DLT-registered SMS.
Calls
Initiate and manage cloud telephony calls, including click-to-call and IVR flows.
Tickets
Support tickets raised by customers across email, chat and telephony channels.
Invoices
Billing documents issued to customers from Custom Applications (Invoicing), including GST details.
Common flows
Send a WhatsApp template · cURL
curl -X POST https://api.office24by7.com/v1/messages/whatsapp \
-H "Authorization: Bearer o24_live_xxx" \
-H "Content-Type: application/json" \
-d '{
"to": "+919812345678",
"template": "order_confirmation",
"language": "en",
"components": [
{ "type": "body", "parameters": [ { "type": "text", "text": "INV-2048" } ] }
]
}'Verify a webhook · Node.js
const crypto = require("crypto");
function verify(rawBody, signature, secret) {
const expected = crypto
.createHmac("sha256", secret)
.update(rawBody, "utf8")
.digest("hex");
return crypto.timingSafeEqual(
Buffer.from(expected),
Buffer.from(signature)
);
}
// app.post('/webhooks', (req, res) => {
// const ok = verify(req.rawBody, req.get("X-O24-Signature"), process.env.O24_WEBHOOK_SECRET);
// res.sendStatus(ok ? 200 : 400);
// });React to events in real time
Office24by7 delivers events to your registered HTTPS endpoint as JSON POST requests, retrying with exponential backoff on non-2xx responses. Verify authenticity by computing an HMAC-SHA256 of the raw request body with your webhook signing secret and comparing it to the X-O24-Signature header.
lead.createdlead.updateddeal.stage_changeddeal.wonmessage.deliveredmessage.failedcall.completedcall.missedticket.createdticket.resolvedinvoice.paidOfficial SDKs
Ready to build?
Create a free workspace, generate sandbox keys in the admin console and ship your first integration today — no sales call required.

