Exterior cleaning for homes, businesses & churches. Greater Memphis, Tennessee & surrounding areas

AUTHORIZED AGENT API

Book with permission. Connect with confidence.

A direct interface for trusted agents arranging in-person quote visits. Start in test mode, review the details with your customer, then book using live access.

Exterior cleaning example

API v1 · SERVER-TO-SERVER

Start here

These appointments are two-hour visits to assess the property and prepare a quote. They do not schedule cleaning or promise a cleaning price. Services are provided by Rolling Suds of Collierville-Southaven.

Download OpenAPI specification Owner credential management ↗

  1. Sign in to the owner admin panel and find Agent booking access. Create a test credential with the permissions below.
  2. Store the credential in your agent server’s secret manager. Send it as Authorization: Bearer YOUR_TOKEN. Browser clients supplying an Origin header are rejected; no cross-origin browser access is offered.
  3. Read the catalog, match the property type to valid service IDs, and fetch availability.
  4. Preview the request. Explain the property, selected services, quote visit time, two-hour duration and service-related contact to the customer. Obtain their approval.
  5. Create the booking with customerApproved: true and a UUID Idempotency-Key. Test mode returns simulated and never writes to Workiz, sends email or reserves live time.
  6. After testing, have the owner issue a separate live credential. Only status: confirmed confirms a real quote visit.

Endpoints and permissions

Base URL: https://midsouthpowerwashing.com/api/v1/agent

RequestPermissionPurpose
GET /catalogcatalog:readProperty types and compatible service IDs
GET /availabilityavailability:readAvailable quote times; synthetic slots in test mode
POST /booking-previewsavailability:readValidate scope and time without reserving or notifying
POST /bookingsbookings:writeCreate a customer-approved quote visit
GET /bookings/{reference}bookings:readRead this credential’s own receipt only

Request example

Replace all customer placeholders and replace appointment: 0 with a start value from availability. Timestamps are Unix seconds, and appointment labels use America/Chicago. Each draft field below must be present; size, access and timing may be empty strings. Property details must be provided even when unknown: use “Unsure” where appropriate.

{
  "draft": {
    "type": "residential",
    "services": [
      "house-wash",
      "driveway",
      "windows"
    ],
    "address": "CUSTOMER STREET ADDRESS",
    "city": "Memphis",
    "state": "TN",
    "zip": "38117",
    "material": "Brick and concrete",
    "size": "Unsure",
    "stories": "1",
    "condition": "Dirt and buildup",
    "water": "yes",
    "access": "",
    "timing": "Flexible",
    "name": "CUSTOMER NAME",
    "email": "CUSTOMER EMAIL",
    "phone": "CUSTOMER PHONE"
  },
  "appointment": 0,
  "customerApproved": true
}

Preview accepts the same body without customerApproved. It never reserves a slot, so creation checks availability again.

Server-side requests

Load MPW_AGENT_TOKEN from your server’s secret store; do not paste real credentials into documentation or shell history.

curl https://midsouthpowerwashing.com/api/v1/agent/catalog \
  -H "Authorization: Bearer $MPW_AGENT_TOKEN"

curl https://midsouthpowerwashing.com/api/v1/agent/bookings \
  -H "Authorization: Bearer $MPW_AGENT_TOKEN" \
  -H "Content-Type: application/json" \
  -H "Idempotency-Key: YOUR_REQUEST_UUID" \
  --data-binary @approved-booking.json

Retries, status and privacy

Limits and credential lifecycle

Credentials expire within 1–90 days. The owner chooses scopes and a limit of 1–50 new bookings per rolling 24-hour window. Each credential allows 60 requests per minute; shared safeguards limit total new bookings and repeated contact to the same customer. A 429 response includes Retry-After; if still limited, wait for the applicable quota window. Failed new attempts may consume quota. Revocation blocks subsequent requests immediately; an already authorized in-flight operation may finish.

Only the credential hash is stored. The full credential is shown once when created and cannot be recovered. Create a replacement and revoke the old credential to rotate access. Test and live credentials are distinct and cannot change environment. Rate limits, validation, encrypted booking storage and audit records protect the API; public website visitors still use its security challenge.

Next steps

Create a test credential, run the read → preview → simulated booking → receipt sequence, and verify that a changed retry and another credential’s receipt are rejected. Issue live access only after that test passes.