Base URL
/v1/supplier/.
Authentication
Every request must carry two headers:X-API-KEY (your API key, issued per supplier contact) and OW-KEY (the OpenWrench shared secret issued alongside it). The key automatically scopes every request to your facility — you only ever see work orders, invoices, and data that belong to you. Requests missing either header return 401.
Rate limits
10 requests per 20-second window per key. Beyond that you’ll receive429 Too Many Requests — wait at least 20 seconds before retrying, and space background jobs (such as full paginated exports) so they stay under the cap.
Keeping work orders in sync
Most supplier integrations exist to mirror the OpenWrench work order queue into another system. Build that on push, not polling:- Register a webhook endpoint. OpenWrench sends
workorder.create,workorder.status_update, andworkorder.new_noteevents as they happen. - On each event, fetch that one work order with
GET /v1/supplier/work_order/work_orders/{id}. - Use
GET /v1/supplier/work_order/work_ordersonly for the one-time initial load and for occasional reconciliation, with a narrow filter and a small page.
Response envelope
Single-entity responses:count:
401 means a missing or invalid key; 400 covers bad input, bad filters, and permission denials; 429 is the rate limit.
Pagination and filtering
List endpoints acceptoffset, limit (default 10, max 25), sort_by, and order (asc | desc). Additional query parameters are treated as field filters — pass a field name with a value (comma-separate multiple values) to filter the result set. Each endpoint’s reference page lists its notable filters.
Date formats
Most timestamps are ISO 8601 strings with offset (e.g.2026-08-14T13:05:22.000-07:00); some database timestamp fields serialize as yyyy-MM-dd HH:mm:ss.S. Plain dates are yyyy-MM-dd.
When sending date-times, use ISO 8601 with a T between the date and time and an explicit offset. A space-separated value such as 2026-09-10 10:43:00+00:00 is not ISO 8601 and is rejected; send 2026-09-10T10:43:00.000+00:00 instead. UTC may be written as +00:00 or Z.
Technician time data
The WrenchMode endpoints expose per-technician work and drive time:GET /v1/supplier/wrench_mode/events/analytics/{fromDate}/{toDate} returns a per-technician drive/work/total rollup (window capped at 1 month), and GET /v1/supplier/wrench_mode/events returns the raw event log behind it. Service-call expansions (/with_work_logs, /with_tech_details) give the per-visit story.
Detailed guides
The guides in this tab walk each part of the API in depth, with payloads, status models, and integration patterns:Work orders
Receive, accept or decline, parts statuses, ECD, attachments, and notes.
Webhooks
New work, status changes, and buyer notes pushed to your endpoint.
Service calls
Schedule, check in, check out, and set the completion status.
WrenchMode
Per-technician analytics and the raw drive/work event log.
Quotes & invoicing
Submit proposals, draft invoices, and publish with a PDF.
Purchasing & inventory
Purchase requests to orders to receipts, catalogs, and stock.
Reference data
Buyer companies, locations, assets, and how data masking works.
Files & users
The file store behind attachments, and technician provisioning.