API reference: every endpoint
Every REST endpoint with its parameters, an example request and response, and the full booking and order objects.
All paths are under https://www.useordina.com/api/v1 and need Authorization: Bearer <key>. See API keys and authentication.
At a glance
| Method | Path | What it does |
|---|---|---|
| GET | /me | The business this key belongs to |
| GET | /appointments | Appointments, newest first |
| GET | /orders | Orders, newest first |
| GET | /webhooks | Your webhook endpoints and the event names |
| POST | /webhooks | Subscribe an https URL to events |
| DELETE | /webhooks/{id} | Unsubscribe |
| GET | /actions | Connected actions |
| POST | /actions | Register a connected action |
| GET | /actions/{id} | One action and its recent calls |
| PATCH | /actions/{id} | Change an action |
| DELETE | /actions/{id} | Remove an action |
| GET | /knowledge | Knowledge you pushed |
| PUT | /knowledge/{key} | Create or replace knowledge |
| DELETE | /knowledge/{key} | Remove knowledge |
GET /me
The business the key belongs to.
{ "id": "6f1c2a8e-...", "handle": "brightsalon", "name": "Bright Salon", "currency": "NGN", "country": "NG" }
| Field | Type | Notes |
|---|---|---|
| id | string (uuid) | Stable. Use it to key your records. |
| handle | string | The last part of the booking link, as in useordina.com/book/brightsalon |
| name | string | The business's display name |
| currency | string | ISO 4217 code for every amount this business returns |
| country | string | ISO 3166-1 alpha-2 |
GET /appointments
| Query | Default | Notes |
|---|---|---|
| limit | 25 | 1 to 100 |
| status | all | For example confirmed, completed, cancelled, no_show |
| since | none | A date, YYYY-MM-DD. Only appointments on or after it. |
GET /api/v1/appointments?status=confirmed&since=2026-10-01&limit=2
{
"data": [
{
"id": 4182,
"status": "confirmed",
"date": "2026-10-03",
"time": "14:30",
"duration_minutes": 90,
"service": { "id": "a7d0...", "name": "Knotless braids", "price": "45000" },
"client": { "name": "Ada Obi", "email": "ada@example.com", "phone": "+2348012345678" },
"payment": { "status": "paid", "amount_paid": 45000, "agreed_amount": null, "currency": "NGN", "reference": "ord_..." },
"location": null,
"notes": "First visit",
"reschedule_count": 0,
"original_date": null,
"original_time": null,
"links": {
"reschedule": "https://www.useordina.com/reschedule/...",
"cancel": "https://www.useordina.com/appointments/cancel/..."
},
"conversation_id": "c0a9...",
"created_at": "2026-09-30T18:02:11.000Z"
}
]
}
The booking object
| Field | Type | Notes |
|---|---|---|
| id | number | |
| status | string | confirmed, completed, cancelled, no_show and similar |
| date, time | string | In the business's time zone |
| duration_minutes | number | |
| service | object | id, name, price (as the business wrote it) |
| client | object | name, email, phone (any can be null) |
| payment | object | status, amount_paid, agreed_amount (a negotiated price), currency, reference |
| location | string or null | A meeting link, or the client's address for a home visit |
| notes | string or null | |
| reschedule_count, original_date, original_time | Set once a booking has moved | |
| links | object or null | The client's own reschedule and cancel pages |
| conversation_id | string or null | The Secretary conversation the booking came from |
| created_at | string |
GET /orders
| Query | Default | Notes |
|---|---|---|
| limit | 25 | 1 to 100 |
| status | all | pending, confirmed, preparing, ready_for_pickup, out_for_delivery, fulfilled, cancelled |
The order object
| Field | Type | Notes |
|---|---|---|
| id | number | |
| status | string | One of the statuses above |
| items | array | Each with service_id, name, qty, unit_price |
| total | number | |
| pay_on_delivery | boolean | True when the customer pays on collection or delivery |
| fulfillment_type | string | pickup or delivery |
| delivery_address, delivery_notes | string or null | |
| tracking_number, carrier | string or null | |
| ready_at, estimated_ready_at | string or null | |
| tracking_url | string or null | The customer's own tracking page |
| client | object | name, email, phone |
| payment | object | status, amount_paid |
| notes, conversation_id, created_at | As for bookings |
Webhooks
GET /webhooks returns { "data": [endpoints], "events": [names] }.
POST /webhooks
{ "url": "https://example.com/ordina/events", "events": ["booking.created", "order.created"], "description": "My app" }
urlmust be https.eventsis optional; leave it out, or send["*"], for every event.- Returns 201 with the endpoint and its
secret, once. - Up to 20 endpoints per business.
DELETE /webhooks/{id} returns 204.
Payloads, signatures and retries: Webhook events and Verify signatures.
Connected actions
POST /actions registers a live lookup the Secretary can call during a chat.
{
"name": "lookup_salary",
"title": "Salary lookup",
"description": "Salary range in Nigeria for a job title, with optional seniority and city. Returns the median and the 25th and 75th percentile in NGN, the number of verified entries and the last update date.",
"url": "https://api.example.com/ordina/lookup-salary",
"parameters": {
"type": "object",
"properties": {
"role": { "type": "string", "description": "Job title, for example Product Manager" },
"level": { "type": "string", "description": "Seniority", "enum": ["Junior", "Mid", "Senior", "Lead"] }
},
"required": ["role"]
}
}
Returns 201 with the action (enabled: false) and its secret, once.
GET /actions returns { "data": [actions] }. GET /actions/{id} adds calls, the 10 most recent. PATCH /actions/{id} takes any of title, description, parameters, url; a new url switches the action off until the owner approves it. DELETE /actions/{id} returns 204.
The action object: id, name, title, description, parameters, url, enabled, source, failureCount, lastCalledAt, lastSuccessAt, lastFailureAt, createdAt, updatedAt. The secret is never returned again.
Everything else about actions: Connected actions.
Knowledge
PUT /knowledge/{key} with { "title": "...", "content": "..." } creates (201) or replaces (200) text the Secretary answers from. GET /knowledge lists it: key, title, chars, updatedAt, createdAt. DELETE /knowledge/{key} returns 204, or 404 when nothing is under that key.
Details and limits: Push knowledge.
