Car dealer API and webhooks
Connect your own website, systems and tools to Vehiso. A JSON REST API for stock, enquiries, customers, sales, appointments and the workshop, with signed webhooks that tell you when something changes.
JSON REST API
One host for every dealer
Signed webhooks
With a delivery log and resend
Scoped keys
Never more than their owner can do
Test sandbox
Build without touching real data
The whole dealership, not just the stock list
The API reaches the same records your team works with in the Vehiso DMS, from the cars on the forecourt to the job cards in the workshop.
Stock
Vehicles, their status and images, with batch upload of stock and photos.
Branches
The branches the dealership trades from.
Enquiries and notes
Enquiries in the dealer's inbox and the notes added to them.
Customers
The dealer's customer records.
Sales
Deals, invoices and payments.
Appointments
Appointments booked with the dealership.
Workshop job cards
Job cards from the workshop.
Part exchange appraisals
Appraisals of vehicles offered in part exchange.
Staff users
The staff accounts at the dealership.
AI website themes
Theme builds and versions from the AI theme builder.
Webhooks and events
Webhook endpoints and the event feed.
Reference lists
The reference lists other records draw on.
Base URL
https://api.vehiso.com/v1
One host serves every dealer. The key you use decides which dealership you are working with.
What developers build with it
From one dealer's bespoke website to an app used by many dealerships.
Bespoke websites
Show live stock on a website you build yourself and send enquiries and valuation requests straight into the dealer's Vehiso inbox. A publishable key is safe in browser code.
Stock sync
Keep stock, prices and photos in step with your own system. Batch upload gets them in, and webhooks keep them in sync.
Reporting and data warehouses
Every list supports updated_since and deletion tombstones, so an incremental sync only fetches what changed.
Website themes
Request, preview and publish website themes through the AI theme builder.
AI assistants
Connect Claude or any Model Context Protocol client through the Vehiso MCP server, and ask about stock, enquiries and appointments in plain English.
Partner integrations
Build an app for many dealerships with OAuth, so each dealer approves your app instead of pasting keys.
Know when something changes
Webhooks tell your system as things happen, and incremental sync means you can always catch up.
Webhooks
- Every delivery is signed, so your endpoint can check it came from Vehiso.
- A delivery log in the Vehiso DMS shows every delivery, and any of them can be resent.
- An endpoint that has been failing for 3 days is disabled automatically, and the dealer gets an email.
Incremental sync
- Every list supports updated_since, so you fetch only what changed since your last sync.
- Deletion tombstones tell you what was removed, so deleted records do not linger in your copy.
- Missed a webhook? Catch up on events from /v1/events.
Access the dealer stays in control of
A dealer administrator creates keys in the DMS under Administration > Developers. A key never does more than its owner could.
Secret keys
For server-side code and integrations. Included in every paid plan.
Publishable keys
Safe in browser code, for websites that show stock and send enquiries. Included in every plan, including Free.
Test keys
Keys starting vh_test_ work against a shared sandbox dealership, never real data.
Scoped to its owner
A key acts as its owner, limited to its scopes and to the owner's current DMS permissions.
Narrow it further
Restrict a key further so an integration only gets what it needs.
Request log
See requests in the request log in the DMS, and match them up by the X-Request-Id on every response.
Simple plans, clear limits
Rate limits apply per key, per minute.
Secret keys
120
requests per minute
Publishable keys
300
requests per minute
OAuth tokens
120
requests per minute
Which plans include the API
- Secret keys, webhooks and OAuth apps are included in every paid plan.
- Publishable keys are included in every plan, including Free.
- Idempotency keys are supported, so a retried request is safe.
From key to first request
The developer docs walk you through it, with the full API reference alongside.
Create a key
A dealer administrator creates one in the DMS under Administration > Developers.
Try it in the sandbox
Use a test key to build against the shared sandbox dealership without touching real data.
Follow the Quickstart
Make your first request with the Quickstart, then build out from the API reference.
Related features
Where the API fits alongside the rest of the platform.
Integrations
The marketplace, finance, accounting and payment integrations that are already built in.
Stock Feed Management
Every channel and advert in one place.
AI Theme Builder
Choose a core theme or describe a bespoke one.
Test Drive & Enquiry
Every enquiry lands in one inbox, including the ones your API integration sends.
Frequently asked questions
What can I build with the Vehiso API?
Bespoke websites that show live stock and send enquiries, stock sync from your own system, reporting and data warehouses, website themes through the AI theme builder, AI assistants through the Vehiso MCP server, and partner apps that dealers approve through OAuth. The API covers stock, branches, enquiries, customers, sales, appointments, workshop job cards, part exchange appraisals, staff users and more.
Which plans include API access?
Secret keys, webhooks and OAuth apps are included in every paid plan. Publishable keys, which are safe to use in website code, are included in every plan, including Free.
How do I get an API key?
A dealer administrator creates keys in the Vehiso DMS under Administration > Developers. There are secret keys for server-side code, publishable keys for browser code and test keys for the sandbox.
Is it safe to put a key in my website's code?
Use a publishable key for that. Publishable keys are safe in browser code, so a bespoke website can show live stock and send enquiries and valuation requests. Keep secret keys on your server.
What can a key access?
A key acts as its owner, limited to its scopes and to the owner's current permissions in the DMS, so it can never do more than that person could. You can narrow a key further, and the request log in the DMS shows the requests it has made.
Can I build and test without touching real data?
Yes. Test keys start vh_test_ and work against a shared sandbox dealership, never a real dealer's data.
How do webhooks work?
You register an endpoint and Vehiso sends it signed deliveries. The DMS keeps a delivery log where any delivery can be resent. If an endpoint keeps failing for 3 days it is disabled automatically and the dealer is emailed, and /v1/events lets you catch up on anything you missed.
What are the rate limits?
Limits apply per key, per minute: 120 requests for a secret key, 300 for a publishable key and 120 for an OAuth token. Idempotency keys are supported, so you can retry a request safely.
Can I connect Claude or another AI assistant?
Yes. The Vehiso MCP server connects Claude or any other Model Context Protocol client, so you can ask about stock, enquiries and appointments in plain English.
Start building with the API
Start a free trial of Vehiso, or read the developer docs to see everything the API can do.

