Help · Reports and documents
Connecting your systems (API)
If your company wants its Drummond jobs, invoices, estimates and requests in its own systems (an ERP or purchasing system, say), ask your Drummond contact for an API key. Each key reads only your company's records, can't change anything, and can be revoked on its own, so ask for one per system.
Reading
Send the key as Authorization: Bearer dk_… with a GET request to /api/v1/jobs, /api/v1/invoices, /api/v1/quotes or /api/v1/requests on this site. Add ?limit= (up to 50) for more than the newest 25. Answers are JSON, newest first, and a key can make 20 calls a minute. /api/v1/ tells you which company and lists the key may read.
Being told when things happen (webhooks)
We can also post to an https address of yours when you make a request, when we reply or change its status, when an order ships, and when one of our local deliveries or pickups is completed. Each post is JSON with a type, data and a version (1 for now; we'll give a new version rather than change this one), and carries an X-Drummond-Signature header, t=<time>,v1=<signature>: the signature is the HMAC-SHA256, in hex, of the time, a full stop and the body, using the secret we give you. Check it, and ignore posts more than five minutes old. Answer with any 2xx status; we try again over a few hours if you don't.