Loading
Loading
Workshop Wrench API
REST API with JSON responses, Bearer token auth, versioned at /v1/. Full OpenAPI 3.0 spec at /docs.
Quick start
Choose your language — all three show the same two-step pattern: get a token, then call the API.
# 1. Authenticate — exchange credentials for a JWT
curl -s -X POST https://api.workshopwrench.com.au/v1/auth/login \
-H "Content-Type: application/json" \
-d '{"email":"[email protected]","password":"demo"}' | jq .accessToken
TOKEN="eyJhbGciOiJIUzI1NiIsInR5cCI6IkpXVCJ9..."
# 2. Fetch open repair orders
curl -s "https://api.workshopwrench.com.au/v1/repair-orders?status=IN_PROGRESS&limit=20" \
-H "Authorization: Bearer $TOKEN" | jq .// 1. Authenticate
const { accessToken } = await fetch(
'https://api.workshopwrench.com.au/v1/auth/login',
{
method: 'POST',
headers: { 'Content-Type': 'application/json' },
body: JSON.stringify({ email: '[email protected]', password: 'demo' }),
}
).then(r => r.json());
// 2. Fetch open repair orders
const { data: orders } = await fetch(
'https://api.workshopwrench.com.au/v1/repair-orders?status=IN_PROGRESS',
{ headers: { Authorization: `Bearer ${accessToken}` } }
).then(r => r.json());
console.log(orders[0].roNumber); // 'RO-1042'import requests
# 1. Authenticate
resp = requests.post(
"https://api.workshopwrench.com.au/v1/auth/login",
json={"email": "[email protected]", "password": "demo"},
)
token = resp.json()["accessToken"]
# 2. Fetch open repair orders
headers = {"Authorization": f"Bearer {token}"}
orders = requests.get(
"https://api.workshopwrench.com.au/v1/repair-orders",
params={"status": "IN_PROGRESS", "limit": 20},
headers=headers,
).json()
print(orders["data"][0]["roNumber"]) # 'RO-1042'Endpoints
Every endpoint is documented in the interactive Swagger UI. Counts are approximate — use the spec for exact routes.
Customer records, contact details, vehicle ownership and service history.
Full RO lifecycle: create, update status, add lines, close, and archive.
Tax invoices, GST line items, payment recording and PDF generation.
Parts catalogue, stock levels, bin locations, reorder rules and PO management.
Booking slots, availability windows, ICS exports and cancellations.
Vehicle records, REGO lookups, service intervals and inspection history.
Fleet accounts, vehicle groups, bulk billing and fleet-specific reporting.
Points balances, redemptions, tier status and membership enrolments.
User accounts, roles, time entries, shifts and commission records.
KPI snapshots, revenue summaries, parts usage and technician productivity.
Register endpoints, list deliveries, retry failures and test payloads.
Tenants, onboarding state, feature flags, comms settings and audit logs.
Authentication
In Workshop Wrench, go to Settings → API & Webhooks. Click "New API key", choose permissions, and optionally set an expiry date.
The full key is shown only once at creation. Copy it to a secrets manager (AWS Secrets Manager, 1Password) — not to version control.
Include the key in every request header: Authorization: Bearer ww_live_...
Token format
ww_live_[32-char random hex]Keys are prefixed ww_live_ for production and ww_test_ for sandbox environments. The prefix (first 8 chars) is shown in the dashboard — the full key is never stored in plaintext.
Rate limits
Limits are per-tenant (not per-IP) on a rolling window. Rate-limit headers are returned on every response.
| Plan | Requests / min | Requests / day |
|---|---|---|
| Starter | 60 | 10,000 |
| Professional | 300 | 100,000 |
| Enterprise | Unlimited | Unlimited |
On limit breach: 429 Too Many Requests with Retry-After header. Response headers: X-RateLimit-Limit, X-RateLimit-Remaining, X-RateLimit-Reset.
Webhooks
Register an HTTPS endpoint at Settings → Webhooks. Events are signed with HMAC-SHA256 in the X-Wrench-Signature header.
ro.createdNew repair order createdro.status_changedRO status transitions (e.g. OPEN → IN_PROGRESS)ro.completedRO marked as complete by a technicianinvoice.paidPayment recorded against an invoiceinvoice.createdInvoice raised from a repair orderbooking.confirmedCustomer booking created and confirmedbooking.cancelledBooking cancelled by staff or customercustomer.createdNew customer record addedinspection.completedDVI inspection marked completeloyalty.points_earnedLoyalty points awarded to a customerparts.low_stockPart stock level dropped below reorder thresholdestimate.approvedCustomer approved a repair estimate via portal{
"event": "ro.status_changed",
"tenantId": "550e8400-e29b-41d4-a716-446655440000",
"timestamp": "2026-09-20T03:14:00.000Z",
"signature": "sha256=abc123...",
"data": {
"id": "ro-uuid",
"roNumber": "RO-1042",
"from": "AWAITING_AUTH",
"to": "IN_PROGRESS",
"changedBy": "user-uuid"
}
}SDKs
Official SDKs are in development. In the meantime, generate a typed client from the OpenAPI 3.0 spec:
npx @openapitools/openapi-generator-cli generate -i http://127.0.0.1:8088/docs-json -g typescript-fetch -o ./wrench-clientJavaScript / TypeScript
Coming soonTyped fetch client for Node.js and browser. Auto-generated from the OpenAPI spec.
Python
Coming soonRequests-based client for scripts, data pipelines, and Django / FastAPI apps.
PHP
Coming soonGuzzle-based client for Laravel and WordPress integrations.
Questions or integration support? Contact the team · Security model · Swagger UI