← API v2 Overview

Authentication & API Keys

Every request authenticates with a per-business API key sent as a bearer token. Keys carry a fixed set of scopes that determine which endpoints they may call.

Getting a Key

API keys are created and managed inside MotorDesk under Business → API. There is no self-serve developer portal; a business user with access to that page issues keys for their own account.

When you create a key you:

  • Give it a name (so usage can be identified later).
  • Choose its scopes from the grouped picker: a key only has the scopes selected at creation. Grant the minimum the integration needs.

The secret is shown once, at creation. Store it securely; it cannot be retrieved again. The same page lists each key's last-used time and lets you revoke a key immediately. To rotate, create a new key, migrate your integration to it, then revoke the old one.

Using the Token

A credential is a key id and secret joined by a dot (key_id.secret). Send it as a bearer token on every request:

curl https://api.motordesk.com/2.0/contacts \
  -H "Authorization: Bearer key_id.secret"
// composer require motordesk/api2
use MotorDesk\Api2\Client;

// The SDK reads the same key_id.secret and sends the bearer header for you.
$client = new Client(apiKey: 'key_id.secret');
$contacts = $client->contacts()->list();
import requests

resp = requests.get(
    "https://api.motordesk.com/2.0/contacts",
    headers={"Authorization": "Bearer key_id.secret"},
)
resp.raise_for_status()
const res = await fetch("https://api.motordesk.com/2.0/contacts", {
  headers: { Authorization: "Bearer key_id.secret" },
});

Authentication failures return 401 (authentication_required, authentication_invalid, authentication_expired, authentication_revoked); a key that authenticates but lacks the required scope returns 403 (scope_denied / scope_required). A frozen or suspended business is locked out of the API entirely, returning 403 (account_frozen / account_suspended) until the account is restored. See Errors.

API access requires the Growth plan or above; it is not available on the Starter plan, on read-only accounts, or on demo accounts. Requests from an ineligible account return 403 (plan_upgrade_required, account_read_only or account_demo).

API 2.0 must also be enabled for the business. Access is requested from the dashboard and granted by our team; until then, and if access is later withdrawn, requests return 403 (api_access_required) even with a valid key.

Cross-Origin (CORS)

The API sends permissive CORS headers and answers preflight OPTIONS requests automatically, so it can be called directly from browser-based tools. Because the bearer secret must stay private, only use it from a browser in trusted, internal contexts - never embed a key in public, client-side code shipped to end users.

Testing Safely

There is currently no sandbox. The API acts on live data and can send customer-facing email (assuming email is set-up), reset passwords, create leads and delete records. To test safely, sign up for a free trial account (business verification required) and issue a key there, kept separate from your live account. If you already have a live account, contact support and we can add a separate developer account you can switch to from the same login.

Discovering a Key's Access

GET /2.0/meta returns the endpoint catalogue available to the calling key, so you can confirm exactly which endpoints and scopes a credential can use before building against them.

Scope Catalogue

The full set of scopes that can be granted to a key. Each endpoint's reference lists the single scope it requires.

Meta

ScopeGrants
meta:readRead API metadata and endpoint catalogue.

Reference

ScopeGrants
reference:readRead reference lists.

Business

ScopeGrants
business:readRead the business profile (contact details, address, localisation and opening hours).

Webhooks

ScopeGrants
webhooks:readRead webhook subscriptions and their deliveries.
webhooks:writeCreate, update, delete, ping and manage webhook subscriptions.

Contacts

ScopeGrants
contacts:readRead contacts.
contacts:writeCreate and update contacts.
contacts:deleteDelete contacts.

Contact Notes

ScopeGrants
contact-notes:readRead contact notes.
contact-notes:writeAdd contact notes.
contact-notes:deleteDelete contact notes.

Contact Login

ScopeGrants
contact-login:writeReset and email contact login details.

Leads

ScopeGrants
leads:readRead leads.
leads:writeCreate and update leads.
leads:deleteDelete leads.

Lead Vehicles

ScopeGrants
lead-vehicles:readRead lead vehicle associations.
lead-vehicles:writeCreate lead vehicle associations.
lead-vehicles:deleteDelete lead vehicle associations.

Lead Messages

ScopeGrants
lead-messages:readRead lead messages.
lead-messages:writeCreate, update, and send lead messages.
lead-messages:deleteDelete lead messages.

Lead Notes

ScopeGrants
lead-notes:readRead lead notes.
lead-notes:writeAdd lead notes.
lead-notes:deleteDelete lead notes.

Lead Appointments

ScopeGrants
lead-appointments:readRead lead appointments.
lead-appointments:writeCreate lead appointments.
lead-appointments:deleteDelete lead appointments.

Appointments

ScopeGrants
appointments:readRead appointments and calendars.
appointments:writeCreate and update appointments and calendars.
appointments:deleteDelete appointments.

Calls

ScopeGrants
calls:readRead VOIP call logs.
calls:writeCreate and update VOIP call logs.

Blog Articles

ScopeGrants
blogs:readRead website blog articles.
blogs:writeCreate and update website blog articles.
blogs:deleteDelete website blog articles.

Reviews

ScopeGrants
reviews:readRead customer reviews.
reviews:writeCreate, update and approve customer reviews.
reviews:deleteDelete customer reviews.

Deals

ScopeGrants
deals:readRead deals.

Listings

ScopeGrants
listings:readRead public listings (advert data only - no business, cost or customer data).

Invoices

ScopeGrants
invoices:readRead invoices.
invoices:writeCreate, edit, issue and cancel invoices.
invoices:paymentRecord invoice payments (mark paid).
invoices:creditRaise and remove invoice credit notes.
invoices:deleteDelete draft invoices.

Orders

ScopeGrants
orders:readRead orders.
orders:writeCreate, edit, issue, cancel and convert orders.
orders:deleteDelete draft orders.

Purchases

ScopeGrants
purchases:readRead purchases.
purchases:writeCreate, edit, issue and cancel purchases.
purchases:paymentRecord purchase payments.
purchases:creditRaise and remove purchase credit notes.
purchases:deleteDelete draft purchases.

Documents

ScopeGrants
documents:readRead document templates.
documents:sendSend documents.

Document Signatures

ScopeGrants
document-signatures:readRead document signature requests.

Vehicle Lookups

ScopeGrants
vehicle-lookups:writeRun vehicle lookups.

Vehicle Recognitions

ScopeGrants
vehicle-recognitions:writeRecognise registrations and VINs.

Vehicle Taxonomy

ScopeGrants
vehicle-taxonomy:readRead vehicle taxonomy values.

Vehicles

ScopeGrants
vehicles:readRead vehicles.
vehicles:writeCreate and update vehicles (including status changes).
vehicles:deleteDelete vehicles.

Vehicle Pricing

ScopeGrants
vehicle-pricing:readRead vehicle pricing and valuations.

Vehicle Lookup

ScopeGrants
vehicle-lookup:readRead third-party vehicle lookup data (DVLA, DVSA, AutoTrader check).

Vehicle Competitors

ScopeGrants
vehicle-competitors:readRead vehicle competitor data.

Vehicle Media

ScopeGrants
vehicle-media:readRead vehicle media.
vehicle-media:writeAttach vehicle media.
vehicle-media:deleteDelete vehicle media.

Vehicle Test Drives

ScopeGrants
vehicle-drives:readRead vehicle test drives.
vehicle-drives:writeStart, end, sign and record vehicle test drives.

Vehicle Reservations

ScopeGrants
vehicle-reserve:readRead vehicle reservations.
vehicle-reserve:writeReserve and cancel vehicle reservations.

Vehicle Appraisals

ScopeGrants
vehicle-appraisals:writeDrive the appraisal offer workflow (request, confirm, accept, decline, reopen).

Vehicle Documents

ScopeGrants
vehicle-documents:readRead and download vehicle documents.
vehicle-documents:writeUpload and update vehicle documents.
vehicle-documents:deleteDelete vehicle documents.

Vehicle Job Boards

ScopeGrants
vehicle-jobs:readRead vehicle job boards (stages, tasks, notes, clocking, documents, purchases).
vehicle-jobs:writeApply job boards and edit their stages, tasks, notes, clocking, documents and purchases.
vehicle-jobs:deleteRemove vehicle job boards and their stages, tasks, notes, clocking and uploads.

Vehicle Descriptions

ScopeGrants
vehicle-descriptions:writeGenerate vehicle advert text.

Search

ScopeGrants
search:wildcardUse wildcard filters where supported.