Vehiso
For developers
Included in paid plans

Car dealer API and webhooks

Connect your own website, systems and tools to Vehiso. A JSON REST API for stock, enquiries, customers, sales, appointments and the workshop, with signed webhooks that tell you when something changes.

JSON REST API

One host for every dealer

Signed webhooks

With a delivery log and resend

Scoped keys

Never more than their owner can do

Test sandbox

Build without touching real data

What it covers

The whole dealership, not just the stock list

The API reaches the same records your team works with in the Vehiso DMS, from the cars on the forecourt to the job cards in the workshop.

Stock

Vehicles, their status and images, with batch upload of stock and photos.

Branches

The branches the dealership trades from.

Enquiries and notes

Enquiries in the dealer's inbox and the notes added to them.

Customers

The dealer's customer records.

Sales

Deals, invoices and payments.

Appointments

Appointments booked with the dealership.

Workshop job cards

Job cards from the workshop.

Part exchange appraisals

Appraisals of vehicles offered in part exchange.

Staff users

The staff accounts at the dealership.

AI website themes

Theme builds and versions from the AI theme builder.

Webhooks and events

Webhook endpoints and the event feed.

Reference lists

The reference lists other records draw on.

Base URL

https://api.vehiso.com/v1

One host serves every dealer. The key you use decides which dealership you are working with.

Full API reference, generated from OpenAPI →
What you can build

What developers build with it

From one dealer's bespoke website to an app used by many dealerships.

Bespoke websites

Show live stock on a website you build yourself and send enquiries and valuation requests straight into the dealer's Vehiso inbox. A publishable key is safe in browser code.

Stock sync

Keep stock, prices and photos in step with your own system. Batch upload gets them in, and webhooks keep them in sync.

Reporting and data warehouses

Every list supports updated_since and deletion tombstones, so an incremental sync only fetches what changed.

Website themes

Request, preview and publish website themes through the AI theme builder.

AI assistants

Connect Claude or any Model Context Protocol client through the Vehiso MCP server, and ask about stock, enquiries and appointments in plain English.

Partner integrations

Build an app for many dealerships with OAuth, so each dealer approves your app instead of pasting keys.

Stay in sync

Know when something changes

Webhooks tell your system as things happen, and incremental sync means you can always catch up.

Webhooks

  • Every delivery is signed, so your endpoint can check it came from Vehiso.
  • A delivery log in the Vehiso DMS shows every delivery, and any of them can be resent.
  • An endpoint that has been failing for 3 days is disabled automatically, and the dealer gets an email.

Incremental sync

  • Every list supports updated_since, so you fetch only what changed since your last sync.
  • Deletion tombstones tell you what was removed, so deleted records do not linger in your copy.
  • Missed a webhook? Catch up on events from /v1/events.
Keys and permissions

Access the dealer stays in control of

A dealer administrator creates keys in the DMS under Administration > Developers. A key never does more than its owner could.

Secret keys

For server-side code and integrations. Included in every paid plan.

Publishable keys

Safe in browser code, for websites that show stock and send enquiries. Included in every plan, including Free.

Test keys

Keys starting vh_test_ work against a shared sandbox dealership, never real data.

Scoped to its owner

A key acts as its owner, limited to its scopes and to the owner's current DMS permissions.

Narrow it further

Restrict a key further so an integration only gets what it needs.

Request log

See requests in the request log in the DMS, and match them up by the X-Request-Id on every response.

Plans and limits

Simple plans, clear limits

Rate limits apply per key, per minute.

Secret keys

120

requests per minute

Publishable keys

300

requests per minute

OAuth tokens

120

requests per minute

Which plans include the API

  • Secret keys, webhooks and OAuth apps are included in every paid plan.
  • Publishable keys are included in every plan, including Free.
  • Idempotency keys are supported, so a retried request is safe.
Get started

From key to first request

The developer docs walk you through it, with the full API reference alongside.

1

Create a key

A dealer administrator creates one in the DMS under Administration > Developers.

2

Try it in the sandbox

Use a test key to build against the shared sandbox dealership without touching real data.

3

Follow the Quickstart

Make your first request with the Quickstart, then build out from the API reference.

Frequently asked questions

What can I build with the Vehiso API?

Bespoke websites that show live stock and send enquiries, stock sync from your own system, reporting and data warehouses, website themes through the AI theme builder, AI assistants through the Vehiso MCP server, and partner apps that dealers approve through OAuth. The API covers stock, branches, enquiries, customers, sales, appointments, workshop job cards, part exchange appraisals, staff users and more.

Which plans include API access?

Secret keys, webhooks and OAuth apps are included in every paid plan. Publishable keys, which are safe to use in website code, are included in every plan, including Free.

How do I get an API key?

A dealer administrator creates keys in the Vehiso DMS under Administration > Developers. There are secret keys for server-side code, publishable keys for browser code and test keys for the sandbox.

Is it safe to put a key in my website's code?

Use a publishable key for that. Publishable keys are safe in browser code, so a bespoke website can show live stock and send enquiries and valuation requests. Keep secret keys on your server.

What can a key access?

A key acts as its owner, limited to its scopes and to the owner's current permissions in the DMS, so it can never do more than that person could. You can narrow a key further, and the request log in the DMS shows the requests it has made.

Can I build and test without touching real data?

Yes. Test keys start vh_test_ and work against a shared sandbox dealership, never a real dealer's data.

How do webhooks work?

You register an endpoint and Vehiso sends it signed deliveries. The DMS keeps a delivery log where any delivery can be resent. If an endpoint keeps failing for 3 days it is disabled automatically and the dealer is emailed, and /v1/events lets you catch up on anything you missed.

What are the rate limits?

Limits apply per key, per minute: 120 requests for a secret key, 300 for a publishable key and 120 for an OAuth token. Idempotency keys are supported, so you can retry a request safely.

Can I connect Claude or another AI assistant?

Yes. The Vehiso MCP server connects Claude or any other Model Context Protocol client, so you can ask about stock, enquiries and appointments in plain English.

Start building with the API

Start a free trial of Vehiso, or read the developer docs to see everything the API can do.