Changelog

What’s new in the API

Every change to the HailMate API and webhooks. Within /v1 we only ever add — new endpoints, fields, events and values — so an integration that ignores fields it doesn’t know keeps working.
  1. Log in with HailMate, and writing money

    Apps can connect by signing in rather than asking for a key, and the API can now create invoices, estimates and door knocks. Everything is additive: nothing was renamed or removed.

    Added
  2. API v2

    The API can now change and delete what it creates, reaches payments, notes, photos, door knocks and hail history, and webhooks cover 30 events with filters — delivered in a second or two. Everything is additive: no field was renamed or removed, and the path is still /v1.

    Added
    • Update and delete jobs, contacts and tasks with PATCH and DELETE. Moving a job with {"stage": "Claim Approved"} runs your stage automations and fires job.stage_changed, exactly as dragging the card does. Deleted jobs and contacts go to Recently Deleted for 30 days.
    • New endpoints: payments (list, get and record), notes, photos and files (upload as a multipart file or from a URL), canvassing pins, pipelines and hail and wind history at an address. A job’s own notes, files, photos, tasks, estimates, invoices and payments, and every job a contact is on.
    • 30 webhook events, up from 8: updated, assigned, completed and deleted; estimates created, sent, viewed and declined; invoices created, sent, overdue and voided; payments received and refunded; notes; photos and files; door knocks and knock results. The catalogue.
    • Webhook filters (“only when a job enters Claim Approved”), "*" for every event including future ones, and events for several events at one URL.
    • Faster, calmer deliveries. Webhooks now arrive in a second or two, where they could take up to a minute. Quick edits to one record arrive as one *.updated delivery listing changed_fields.
    • Idempotency keys on every POST, PATCH and DELETE, remembered for 24 hours.
    • X-Request-Id and X-RateLimit-Limit / -Remaining / -Reset on every response, and a request_id in every error.
    • Read-only keys, for reporting tools that should never change anything.
    • In Settings: rotate a webhook’s secret with a 24-hour overlap, Send test, Resend, a delivery log, and a log of every request a key made, kept for 14 days.
    • updated_since, created_after and created_before on every list, and new list filters such as pipeline_id, assigned_to and contact_id on jobs.
    • Money on every job — total_job_value, amount_received, balance_due — and package_totals on estimates.
    Changed
    • Task and appointment times are wall-clock. A due_date sent with an offset keeps its digits and drops the offset — 2026-10-02T15:00:00-05:00 is 3:00 PM on the crew’s calendar. Before, an offset could shift the appointment by hours.
    • A job search with no criteria returns an empty list. It used to return the newest job, which is how a blank search step wrote to the wrong job.
    • An estimate’s total now honours a stated package price and standalone packages, matching the PDF the homeowner sees.
    Fixed
    • assigned_to must be someone on your own team.
    • An unknown stage is a 400 naming stage, instead of a job that landed in no column.
    • A malformed date, enum value or cursor is a 400 rather than a 500.
    • A webhook switched off after repeated failures now tells the workspace’s owners and admins.
    • GET /users lists only your own team.
  3. API v1 launched

    The first public release of the HailMate API and webhooks, on every paid plan.

    Added
    • API keys, made by owners and admins in Settings → Integrations → API & Webhooks. A key belongs to one workspace.
    • Read jobs, contacts, tasks and appointments, estimates, invoices, and storm lists with their properties. Search jobs by address, number or name, and contacts by email, phone or name — phone numbers matched however they were typed.
    • Create contacts, jobs, tasks, appointments and notes.
    • Stages, users and the event catalogue, for building dropdowns.
    • Webhooks for 8 events — job.created, job.stage_changed, contact.created, task.created, appointment.created, estimate.signed, invoice.paid and storm_list.ready — signed with HMAC-SHA256 and retried, plus sample payloads from GET /webhooks/samples/{event}.
    • Cursor pagination, updated_since, and a limit of 120 requests a minute per key.