Bizkar CRM API
Last updated 30 September 2026
Connect Zapier, Make, Pabbly Connect or your own scripts to your Bizkar organization: create and update leads, contacts, customers, deals, tickets, activities and notes, convert leads, and read quotes and contracts.
The reference
Every route, field and error is in the OpenAPI document:openapi-v1.json. Paste it into Swagger Editor, Postman or Insomnia to browse and try it. The API also serves it at https://crm-api-int.bizkar.in/api/v1/openapi.json.
Authentication
- An owner or admin makes an API key in Bizkar under Settings → API keys, on any paid plan. The key is shown once; keep it like a password.
- Send it with every request:
Authorization: Bearer bzk_…. The base URL ishttps://crm-api-int.bizkar.in/api/v1. - A key acts in one organization, with the permissions of the role it was given. In modules your organization shows only to each record's owner and managers, a key sees every record only if its role can see every record; otherwise it reaches the unassigned ones.
- Call
GET /api/v1/meto check a key: it answers with the organization and what the key may do. - Revoking a key stops it at the next request.
How it behaves
- Writes follow the same rules as the app.
PUTreplaces the whole record, so send every field you want to keep. A lead or ticket you create without an assignee goes to the first matching assignment rule (Settings → Assignment). Otherwise a lead, contact, deal or activity goes to the organization's default assignee, which is the owner unless someone chose another, and a ticket stays unassigned until someone takes it. - Lists take
page(from 1) andpageSize(up to 100) and answeritemswithtotalCount. - Errors are problem details: a
typenaming the problem (for example…/errors/plan-requiredor…/errors/validation-failed) and a readabledetail. - Limits: 120 requests a minute per key; past that,
429withRetry-After. - History: every change a key makes is recorded in the record's history under the key's name.
Webhooks
Instead of asking the API what changed, have Bizkar tell you. Under Settings → Webhooks, on any paid plan, add an https:// address and choose its events: lead.created,lead.converted, deal.won, deal.lost, quote.accepted,ticket.created, ticket.late (it missed its response time), ticket.closed,contract.expiring (a renewing contract, 30 days before it ends) and contract.expired.
- Each event is a
POSTwith a JSON body:id(the event's),type,occurredAt,organizationIdanddata, the record as the API'sGETshows it. - Check the signature. The header
X-Bizkar-Signature: t=1760000000,v1=5f2b…holds the time it was signed (Unix seconds) and a hex HMAC-SHA256, keyed with the webhook's signing secret (shown once, when you add it), of the time, a dot, and the raw body:HMAC(secret, t + "." + body). Compute it over the bytes you received, compare in constant time, and refuse atmore than five minutes old. - Answer with any
2xxwithin 10 seconds. Anything else, a redirect or no answer is a failure, and the delivery is tried again after 1, 5 and 30 minutes, then every few hours, for a day. - An event can arrive more than once, and a resend from the delivery log is the same event again: use
idto skip ones you have handled. Deliveries are not ordered. - After five days in which nothing got through, the webhook is turned off, and the owners and whoever manages integrations are told by email. Turn it back on from the same page.
- Webhooks go only to public addresses, never to a private or local network.
Versions
Within v1, changes only add: new fields, routes and values. Anything that would break an existing integration comes as v2, and a version is retired only with six months' notice.