Build on Floorplate360
REST API, webhooks, and embeds. Per-operator keys; every request scoped to your data.
Authentication
Create an API key in your workspace under Admin → Integrations. Keys are scoped to one operator with read or read + write scopes, shown once, and revocable. Send it as x-api-key or as a bearer token. The API lives on your workspace's own address, not a shared host.
curl https://your-workspace.floorplate360.com/api/v1/members \ -H "Authorization: Bearer fp_live_..."
Operator API
Requires a key.
GET /api/v1/members— members with company and subscriptions;?since=for incremental syncPOST /api/v1/members— create or update a member by email (write scope)GET /api/v1/subscriptions— plan, space, member, and billing periodGET /api/v1/invoices— accounting export;?from=and?to=datesGET /api/v1/mail— mail items and their statusPOST /api/v1/imports— bulk onboarding from an OfficeRnD, Nexudus, Cobot, or CSV export;?commit=trueto apply clean rows
Public endpoints
No key. Scoped to the workspace by hostname, or by ?operator=<slug> when called from another site. Read-only except where noted; they return only what a visitor could see.
GET /api/v1/brand— name, logo, colors, fontsGET /api/v1/locations— address, timezone, business hoursGET /api/v1/plans— public price list with live availabilityGET /api/v1/roomsandGET /api/v1/availability— bookable rooms and open start timesPOST /api/v1/bookings— guest room booking; returns a Stripe Checkout linkPOST /api/v1/leads— inquiry or waitlist signup
Members use /api/v1/me/* with their own sign-in token; that is what the mobile app runs on. Not exposed yet: spaces and floor-plan inventory, companies, landlord statements, and room display devices. Tell us if you need one.
Webhooks
Register endpoints under Admin → Integrations and pick events, or * for all. Deliveries are signed with HMAC-SHA256 over <timestamp>.<body> using the endpoint secret, sent as x-floorplate-signature: t=<timestamp>,v1=<hex> with the event name in x-floorplate-event. Failed deliveries retry after 1 minute, 5 minutes, 30 minutes, 2 hours, and 12 hours.
Events: booking.confirmed, booking.cancelled, subscription.started, subscription.notice_given, subscription.ended, invoice.paid, invoice.past_due, mail.received, member.created, member.access_changed, announcement.published, visitor.arrived.
{
"event": "booking.confirmed",
"at": "2026-11-12T19:00:04Z",
"data": {
"booking_id": "7d3e…",
"space_id": "a91c…",
"member_id": "f204…",
"guest_email": null,
"start": "2026-11-12T19:00:00Z",
"minutes": 60
}
}Room displays
Room display devices are not exposed through the API yet. When pairing ships, each device will load a tokenized page for one room only — no member data on the wire — and each token will be revocable on its own from the operator admin.
Drop-in widgets for your marketing site, in your brand: plans (price list with live availability) and book (guest room booking with checkout). One script tag; the iframe sizes itself.
<script src="https://your-workspace.floorplate360.com/embed.js" data-operator="your-workspace" data-widget="plans"></script>
Public form endpoints are limited to 10 requests per IP per 10 minutes. Imports take up to 5,000 rows per call; lists return up to 1,000 rows (invoices 2,000). Webhook deliveries time out after 10 seconds.
API changes are announced to the email on your operator account before they ship. Breaking changes ship as a new version path with an overlap period. A public status page is not set up yet.