# Zoca > Zoca is an AI-powered marketing platform for local beauty and wellness businesses — salons, spas, med spas > and wellness clinics. It packages its automation as agents: a Discovery Agent (local SEO, Google Business > Profile, website), a Win Agent (converts enquiries into confirmed appointments over chat, SMS and voice), a > Loyalty Agent (rebooking and retention) and a Social Agent (Instagram, TikTok, Facebook content). Zoca is > operated by ZOCAAI TECHNOLOGIES PRIVATE LIMITED, founded 2021, and is an Accel portfolio company. Generated by API Evangelist on 2026-08-13. Zoca serves no llms.txt of its own — /llms.txt returns 404 on zoca.com, zoca.ai, api.zoca.ai, tasks.zoca.ai and public.zoca.com. ## What an agent should know first Zoca has **no developer program**: no developer portal, no API reference, no API documentation, no SDK, no sign-up for API access, no published rate limits and no terms covering API use. It nevertheless serves **three real OpenAPI 3.0.0 documents publicly and unauthenticated**, at `/swagger.json` on three hosts. These are the application's own backend contracts — the surface its web app, mobile apps and booking widget call — not a product Zoca sells. Treat them as undocumented and unsupported: there is no versioning policy, no deprecation policy, no changelog and no status page, so they can change without notice. Two defects make them hard for machines to consume: `operationId` is the literal string `t_value` on 2,621 of the 2,624 operations, and `components.schemas` holds only anonymous minified schemas (`e`, `t`, `Object`), so no request or response body is typed. Identify operations by METHOD + path. ## APIs - [Zoca Platform API](https://api.zoca.ai): 1,413 paths / 1,700 operations. Scheduling and bookings, website generation and custom domains, Google Business Profile, discovery/local SEO, social media, services and staff, clients, offers and packages, booking enquiries, billing (Chargebee), and the "brain" agent layer. - [Zoca Tasks API](https://tasks.zoca.ai): 785 paths / 855 operations under `/tasks/api/v1`. AI content queue and planning, FrontDesk voice + SMS agent onboarding (Retell, Twilio), the embeddable booking widget, local-SEO grid scans, WIN conversion triggers, and inbound integration webhook receivers. - [Zoca Public API](https://public.zoca.com): 69 operations, reachable **unauthenticated**. Backs the free self-serve tools on zoca.com — keyword demand, Google Business Profile competitor analysis, place metrics, website strategy grading and pricing benchmarks. ## Specs - [Zoca Platform OpenAPI](https://raw.githubusercontent.com/api-evangelist/zoca/refs/heads/main/openapi/zoca-platform-openapi.yml) - [Zoca Tasks OpenAPI](https://raw.githubusercontent.com/api-evangelist/zoca/refs/heads/main/openapi/zoca-tasks-openapi.yml) - [Zoca Public OpenAPI](https://raw.githubusercontent.com/api-evangelist/zoca/refs/heads/main/openapi/zoca-public-openapi.yml) - Unmodified originals as served by Zoca: `openapi/_original/zoca-{platform,tasks,public}-swagger.json` - [Live source](https://api.zoca.ai/swagger.json) — also `https://tasks.zoca.ai/swagger.json` and `https://public.zoca.com/swagger.json` ## Authentication Bearer JWT. `Authorization: Bearer `, security scheme `access-token`, declared identically in all three documents. No OAuth 2, no OpenID Connect, no API keys, no scopes — `/.well-known/openid-configuration` and `/.well-known/oauth-authorization-server` 404 on every Zoca host. There is no way to obtain a token without a Zoca account; the app uses passwordless magic-link login (`POST /auth/magic-link/request`, rate limited to 5 requests per email per 5-minute window — the only numeric rate limit Zoca publishes anywhere). ## Conventions and semantics - [Conventions](https://raw.githubusercontent.com/api-evangelist/zoca/refs/heads/main/conventions/zoca-conventions.yml) — auth, idempotency, pagination (`page`/`limit`/`pageSize`), versioning, error envelope - [Error catalog](https://raw.githubusercontent.com/api-evangelist/zoca/refs/heads/main/errors/zoca-problem-types.yml) — NestJS `{statusCode, message, error}`; **not** RFC 9457 - [Rate limits](https://raw.githubusercontent.com/api-evangelist/zoca/refs/heads/main/rate-limits/zoca-rate-limits.yml) — 429 on 11 operations; **no** `RateLimit-*` or `Retry-After` headers anywhere - [Data model](https://raw.githubusercontent.com/api-evangelist/zoca/refs/heads/main/data-model/zoca-data-model.yml) — `{entityId}` (a business location) is the root scope - [Lifecycle](https://raw.githubusercontent.com/api-evangelist/zoca/refs/heads/main/lifecycle/zoca-lifecycle.yml) — no status page, no SLA, no deprecation policy, no changelog ## Agent surfaces - [Agent Skills](https://raw.githubusercontent.com/api-evangelist/zoca/refs/heads/main/skills/_index.yml) — four packaged flows: book an appointment, capture and convert a lead, run a local discovery audit, manage the content queue - [MCP](https://raw.githubusercontent.com/api-evangelist/zoca/refs/heads/main/mcp/zoca-mcp.yml) — **candidate only.** Zoca ships no MCP server, remote or stdio. - **No A2A agent card.** `/.well-known/agent-card.json` and `/.well-known/agent.json` 404 on all six hosts. - **No customer-facing webhooks.** The 50 webhook/callback endpoints in the contracts are inbound receivers for Zoca's own vendors (Stripe, Twilio, Chargebee, Square, Pipedrive, Retell, CallHippo, Sybill, Instantly, Boulevard, Mindbody). See [webhooks](https://raw.githubusercontent.com/api-evangelist/zoca/refs/heads/main/asyncapi/zoca-webhooks.yml). - **No `/.well-known/` documents of any kind.** See [well-known](https://raw.githubusercontent.com/api-evangelist/zoca/refs/heads/main/well-known/zoca-well-known.yml). ## Security and compliance - [Trust Center](https://trust.zoca.com/) — Sprinto-hosted. HIPAA compliant; GDPR "coming soon". No SOC 2, no ISO 27001. Returns HTTP 403 to a non-browser User-Agent. - No security.txt, no vulnerability disclosure policy, no bug bounty, no published security contact. - [Domain security](https://raw.githubusercontent.com/api-evangelist/zoca/refs/heads/main/security/zoca-domain-security.yml) — TLS 1.3 everywhere; no HSTS on zoca.com or api.zoca.ai; no DNSSEC, no CAA on zoca.com or zoca.ai. ## Docs and site - [Website](https://zoca.com/) - [Pricing](https://zoca.com/pricing) — three tiers (Essential, Grow, Thrive); **no prices published**, demo-gated - [Blog](https://zoca.com/blog) - [Discovery Agent](https://zoca.com/discovery-agent) · [Win Agent](https://zoca.com/win-agent) · [Loyalty Agent](https://zoca.com/loyalty-agent) · [Social Agent](https://zoca.com/social-agent) - Free tools: [keyword analysis](https://zoca.com/free-tools/keywords-analysis) · [website strategy](https://zoca.com/free-tools/website-strategy) · [GBP strategy](https://zoca.com/free-tools/gbp-strategy) - [Customers](https://zoca.com/customers) · [About](https://zoca.com/about-us) · [Contact](https://zoca.com/contact-us) · [Careers](https://zoca.com/careers) - [Terms of Use](https://zoca.com/terms-of-use) · [Privacy](https://zoca.com/privacy) - [App login](https://app.zoca.com/login) · [Book a demo](https://zoca.com/demo) - [GitHub organization](https://github.com/zoca-ai) — 2 public repos, neither an SDK - Mobile: [iOS](https://apps.apple.com/us/app/zoca-grow-your-local-business/id6738140998) · [Android](https://play.google.com/store/apps/details?id=com.zoca.ai)