openapi: 3.0.3 info: title: HoneyBook API (Modeled) Clients API description: HoneyBook does not publish a self-serve public developer API or a public API reference. This document models the logical resource surface implied by HoneyBook's product (clients/leads, projects, contracts, proposals, invoices, payments, scheduler sessions) and by the trigger/action events exposed through its Zapier integration (New Client, New Inquiry, Project Booked, Payment Received, Project Stage Changed). An internal API host, https://api.honeybook.com, is live behind Cloudflare and clearly backs HoneyBook's own web/mobile apps and its native integrations, but HoneyBook has never published endpoint documentation, a client registration/OAuth flow, or a field dictionary for outside developers. Third-party integration guides (e.g. Rollout) reference an OAuth 2.0 flow against api.honeybook.com and a `/v1/` base path, but are inconsistent with each other on the exact token endpoint and grant type, and are not independently verifiable - treat every path, parameter, and schema below as an honest, sourced-but-unverified model, not a confirmed reference. Confirm directly with HoneyBook before attempting integration. version: 1.0-modeled contact: name: HoneyBook url: https://www.honeybook.com servers: - url: https://api.honeybook.com/v1 description: Modeled base path (unverified; not publicly documented by HoneyBook) security: - oauth2: [] tags: - name: Clients description: Clients and inquiries/leads captured through HoneyBook lead forms. paths: /clients: get: operationId: listClients tags: - Clients summary: List clients and inquiries description: Modeled from the "New Client" and "New Inquiry" Zapier triggers. Not a confirmed HoneyBook endpoint. parameters: - name: page in: query schema: type: integer default: 1 - name: status in: query description: Filter by lead status (e.g. inquiry, client). schema: type: string responses: '200': description: A page of clients/inquiries. content: application/json: schema: type: object properties: data: type: array items: $ref: '#/components/schemas/Client' '401': $ref: '#/components/responses/Unauthorized' post: operationId: createClient tags: - Clients summary: Create a client or inquiry requestBody: required: true content: application/json: schema: $ref: '#/components/schemas/ClientInput' responses: '201': description: The created client. content: application/json: schema: $ref: '#/components/schemas/Client' '401': $ref: '#/components/responses/Unauthorized' '422': $ref: '#/components/responses/ValidationError' /clients/{id}: parameters: - $ref: '#/components/parameters/Id' get: operationId: getClient tags: - Clients summary: Retrieve a client responses: '200': description: The requested client. content: application/json: schema: $ref: '#/components/schemas/Client' '401': $ref: '#/components/responses/Unauthorized' '404': $ref: '#/components/responses/NotFound' patch: operationId: updateClient tags: - Clients summary: Update a client requestBody: required: true content: application/json: schema: $ref: '#/components/schemas/ClientInput' responses: '200': description: The updated client. content: application/json: schema: $ref: '#/components/schemas/Client' '401': $ref: '#/components/responses/Unauthorized' '404': $ref: '#/components/responses/NotFound' components: responses: Unauthorized: description: Missing or invalid access token. content: application/json: schema: $ref: '#/components/schemas/Error' NotFound: description: The requested resource was not found. content: application/json: schema: $ref: '#/components/schemas/Error' ValidationError: description: The request payload failed validation. content: application/json: schema: $ref: '#/components/schemas/Error' schemas: ClientInput: type: object required: - name - email properties: name: type: string email: type: string format: email phone: type: string status: type: string enum: - inquiry - client Client: allOf: - $ref: '#/components/schemas/ClientInput' - type: object properties: id: type: string created_at: type: string format: date-time Error: type: object properties: error: type: object properties: code: type: string message: type: string parameters: Id: name: id in: path required: true description: The unique identifier of the resource. schema: type: string securitySchemes: oauth2: type: oauth2 description: Third-party integration guides reference OAuth 2.0 against api.honeybook.com, but are inconsistent on the exact token endpoint and grant type and are not independently verifiable. Modeled here as an authorization-code flow with refresh tokens, the most common pattern for a user-data platform of this kind; treat as unverified. flows: authorizationCode: authorizationUrl: https://api.honeybook.com/oauth/authorize tokenUrl: https://api.honeybook.com/oauth/token scopes: clients.read: Read clients and inquiries. clients.write: Create and update clients and inquiries. projects.read: Read projects and pipeline stage. projects.write: Create and update projects. contracts.read: Read contracts. contracts.write: Create contracts. proposals.read: Read proposals. proposals.write: Create proposals. invoices.read: Read invoices. invoices.write: Create invoices. payments.read: Read payments. scheduler.read: Read session types and bookings. scheduler.write: Create bookings. webhooks.write: Manage webhook subscriptions. externalDocs: description: HoneyBook integrations and partnerships help center url: https://help.honeybook.com/en/collections/68941-integrations-and-partnerships