Co-Labs · The back office
Your tool reads the diary, and every appointment reaches it signed.
Three reads under one key, three events by webhook: a business’s free hours in your tool, its diary followed closely — and not one piece of its clients’ data.
You read three things about a business, and each one is a commitment
Under /api/v1/public, you read the business’s identity, its active catalogue and the slots for one day; any other address answers 404, with the list of the three routes.
Every field you receive is a commitment: our internal model may change, what you read does not; a price worked out on the premises is given as ‘on request’, never 0.
- Every responseits contract version, the business identifier, the
X-Api-Versionheader - Every errora stable
codeto test against, a readable message - Cache-Control: private, no-storeon every response, rate-limit refusals included
salon
Identifier, name, trade, time zone, booking address.
services
Active catalogue: name, category, duration, price in CHF, variants.
availability
The slots for one day for a given service, person by person.
You read the business’s time, and ‘closed’ is distinct from ‘full’
‘14:30’ is 14:30 on the premises: every time is expressed in the business’s time zone, which the salon route gives you.
Your slots follow the business’s rules: the team’s hours, time off, closures; a service that first requires a visit returns no schedule. Two flags say why a day is empty.
Closed
The business does not open that day: nothing to offer.
Full
The business is open, and there is nothing left to offer that day.
Your key opens one business, read-only, and nothing else
We hand it to you with a label and your technical contact address; it is shown once only, and we keep nothing but its fingerprint. Two tools, two keys.
Your data comes from your key, never from the address called: your key reads only your data, on your domain as on your Co-Labs address. An internal token opens nothing here.
- Form
clk_followed by 32 randomly drawn bytes - Header
Authorization: BearerorX-API-Key - Scopea single one,
public:read: no writing in v1 - Rate120 requests per minute, counted per key
Every appointment reaches you, signed
Created, cancelled or moved — on the website, with Liah on the phone or in writing, at the counter — the appointment is announced to you by a signed POST, entry channel included; a test in our repository checks that every path that writes an appointment announces it.
Every delivery carries Colabs-Signature: t=<timestamp>,v1=<HMAC-SHA256>, computed over the timestamp and the body as it leaves. Check it in constant time, within a five-minute window; Colabs-Event-Id and Colabs-Attempt let you de-duplicate a retry.
- Events
rdv.cree,rdv.annule,rdv.deplace, and not one more - Secretone per subscription, shown once, encrypted at rest
- Payloadan opaque reference, date, time, duration, service, status, channel
- No personal datano name, no phone number, no email, no note
- Dry runa
webhook.testfrom our console
Your server can go down: the event waits for you
Nothing leaves during the client’s booking: the event is kept on our side and then carried to you, and the booking goes through even if your server is under maintenance. Seven attempts over about 8 hours 45 minutes: an appointment for the next morning arrives in time.
A 2xx response counts as success; everything else is a failure, redirects included. After five abandonments in a row, the subscription pauses; we restart it with you, counter reset to zero.
- Attemptsimmediate, then 10 s, 1 min, 5 min, 30 min, 2 h, 6 h
- Deadline10 seconds per delivery
- Your addressHTTPS required, private addresses refused, no redirect followed
- Memorya completed delivery is erased after 30 days, a pending delivery never is
Your integration holds over time
The version lives in the path, v1, and the contract revision in every response. A field, a route or a value may be added: allow for a default case. Nothing that exists disappears or changes meaning — that would be a v2, and our written contract then holds v1 for at least twelve months, with the Deprecation and Sunset headers.
The contact address left when the key is handed over is required: that is how we notify you.
Keys and subscriptions are set up and cut off with us, from our console — not yet from the business’s back office; notice of a change goes out by our hand. The other limits live on a single page.
Want to see it under your business’s name?