API reference

DocumentLane exposes HTTP endpoints for payment webhooks, scheduled jobs and integration callbacks. All endpoints are served over HTTPS from the base URL below and exchange JSON.

https://documentlane.ai

Authentication

  • Webhooks are verified with the sender's HMAC signature over the raw body.
  • Scheduled jobs require a bearer job token in the Authorization header.
  • OAuth callbacks validate a one-time state value tied to your organization.
  • In-app operations (clients, documents, templates) require a signed-in session and are not part of the public API.

Errors

Standard HTTP status codes are used. Error bodies are plain text or { "error": "message" }.

400Bad request — invalid input or signature
401Unauthorized — missing or invalid credentials
403Forbidden — plan or role does not allow this
404Not found
500Server error — safe to retry
POST/api/public/payments/webhook

Receives subscription and checkout events from the payment provider and updates the organization's plan.

Authentication

Signed payload. The provider's signature header is verified against the raw request body before any processing.

Example request body

{
  "type": "customer.subscription.updated",
  "data": { "object": { "id": "sub_123", "status": "active", "items": { ... } } }
}

Example response

{ "received": true }

Responses

  • 200 — Event processed or safely ignored
  • 400 — Missing or invalid signature / malformed body
  • 500 — Processing failed — the provider will retry
POST/api/public/cron/expirations

Daily job that sends expiry reminders for documents expiring soon and marks expired documents. Reminders are de-duplicated per document and window.

Authentication

Bearer job token: Authorization: Bearer <job token>. Tokens are issued by DocumentLane and stored privately.

Example response

{ "ok": true, "reminders_sent": 12, "expired": 3 }

Responses

  • 200 — Run completed
  • 401 — Missing or invalid job token
  • 500 — Run failed
GET/api/public/integrations/procore/callback

OAuth 2.0 redirect target for connecting a Procore company. Exchanges the authorization code and stores credentials server-side.

Authentication

OAuth state parameter, validated against the organization that started the connection.

Query parameters

  • code — Authorization code returned by Procore
  • state — Opaque state issued when the connection started

Example response

302 redirect to /app/settings?tab=integrations

Responses

  • 302 — Connected — redirects back to Settings
  • 400 — Missing or invalid code/state