Developers
API and webhooks
Connect your website, CRM, e-commerce store or accounting to Cling Works. JSON over HTTPS, one key per integration, and signed webhooks for what happens in the factory.
Authentication
Create a key in Settings → API. Send it as a bearer token. Keys are read-only unless you give them write access; revoke one and it stops working immediately. Each key may make 120 requests a minute.
curl https://app.clinginfotech.com/api/v1/items?q=bracket \
-H "Authorization: Bearer cwk_xxxxxx_…"Endpoints
Base URL https://app.clinginfotech.com/api/v1. Lists return { data, page, per_page, total }; money is a string in rupees.
- GET/itemsItems, 50 a page. ?q= searches name and SKU; ?page= and ?per_page= (max 100) page through. (read)
- GET/items/{id}One item. (read)
- POST/itemsCreate an item: name, sku, kind, uom, hsn_code, gst_rate, sale_price. (write)
- GET/customersCustomers and suppliers. ?q= searches name and GSTIN. (read)
- POST/customersCreate a customer: name, gstin, email, phone, state_code, is_supplier. (write)
- POST/enquiriesSend an enquiry into the inbox: message, subject, contact {name, company, email, phone}, external_id (makes retries safe). (write)
- GET/quotesQuotes, newest first. (read)
- GET/sales-ordersSales orders, newest first. (read)
- GET/invoicesInvoices with totals, amount paid and IRN. (read)
- GET/stockStock by item: on hand, reserved, on order, in quality hold. (read)
Errors come back as JSON with a code — unauthorized (401), forbidden (403), not_found (404), invalid (422, with the fields that need fixing), rate_limited (429).
curl -X POST https://app.clinginfotech.com/api/v1/enquiries \
-H "Authorization: Bearer cwk_…" -H "Content-Type: application/json" \
-d '{"message":"Need 500 MS brackets, 3mm, zinc plated","contact":{"name":"Ravi","email":"ravi@buyer.in"},"external_id":"web-4471"}'Webhooks
Add an endpoint in Settings → API and pick the events. We POST JSON within a minute of the event and retry failures after 1, 5, 30, 120 minutes, 12 and 24 hours.
{
"id": "9c1f…", "type": "invoice.issued", "createdAt": "2026-09-22T10:31:07Z",
"data": { "entityType": "invoice", "entityId": "0192…" }
}Check every call: the x-cling-signature header is t=<unix seconds>,v1=<hex>, where v1 is HMAC-SHA256 of "t.body" with your endpoint's signing secret. Reject calls older than five minutes.
const [t, v1] = sig.match(/t=(\d+),v1=(\w+)/).slice(1);
const ok = crypto.createHmac("sha256", secret).update(`${t}.${rawBody}`).digest("hex") === v1;Events: enquiry.received, quote.sent, quote.won, quote.lost, sales_order.created, sales_order.dispatched, invoice.issued, invoice.payment_recorded, invoice.cancelled, work_order.completed, purchase_order.sent, purchase_order.received, delivery_challan.issued, approval.requested, approval.approved, approval.rejected.