API reference
DocumentLane exposes HTTP endpoints for payment webhooks, scheduled jobs and integration callbacks. All endpoints are served over HTTPS from the base URL below and exchange JSON.
https://documentlane.aiAuthentication
- Webhooks are verified with the sender's HMAC signature over the raw body.
- Scheduled jobs require a bearer job token in the Authorization header.
- OAuth callbacks validate a one-time state value tied to your organization.
- In-app operations (clients, documents, templates) require a signed-in session and are not part of the public API.
Errors
Standard HTTP status codes are used. Error bodies are plain text or { "error": "message" }.
| 400 | Bad request — invalid input or signature |
| 401 | Unauthorized — missing or invalid credentials |
| 403 | Forbidden — plan or role does not allow this |
| 404 | Not found |
| 500 | Server error — safe to retry |
/api/public/payments/webhookReceives subscription and checkout events from the payment provider and updates the organization's plan.
Authentication
Signed payload. The provider's signature header is verified against the raw request body before any processing.
Example request body
{
"type": "customer.subscription.updated",
"data": { "object": { "id": "sub_123", "status": "active", "items": { ... } } }
}Example response
{ "received": true }Responses
200— Event processed or safely ignored400— Missing or invalid signature / malformed body500— Processing failed — the provider will retry
/api/public/cron/expirationsDaily job that sends expiry reminders for documents expiring soon and marks expired documents. Reminders are de-duplicated per document and window.
Authentication
Bearer job token: Authorization: Bearer <job token>. Tokens are issued by DocumentLane and stored privately.
Example response
{ "ok": true, "reminders_sent": 12, "expired": 3 }Responses
200— Run completed401— Missing or invalid job token500— Run failed
/api/public/integrations/procore/callbackOAuth 2.0 redirect target for connecting a Procore company. Exchanges the authorization code and stores credentials server-side.
Authentication
OAuth state parameter, validated against the organization that started the connection.
Query parameters
code— Authorization code returned by Procorestate— Opaque state issued when the connection started
Example response
302 redirect to /app/settings?tab=integrationsResponses
302— Connected — redirects back to Settings400— Missing or invalid code/state